2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32939 | LOW | 3.7 | 0.2% | Aug 22, 2024 | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, ... |
| CVE-2024-45169 | CRITICAL | 9.8 | 1.4% | Aug 22, 2024 | An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper de... |
| CVE-2024-45168 | CRITICAL | 9.1 | 0.7% | Aug 22, 2024 | An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is transferred over a raw socket without... |
| CVE-2024-45167 | CRITICAL | 9.8 | 1.2% | Aug 22, 2024 | An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper de... |
| CVE-2024-45166 | CRITICAL | 9.8 | 1.0% | Aug 22, 2024 | An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper de... |
| CVE-2024-45165 | MEDIUM | 5.3 | 0.2% | Aug 22, 2024 | An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with e... |
| CVE-2024-45163 | CRITICAL | 9.1 | 0.8% | Aug 22, 2024 | The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Una... |
| CVE-2024-7836 | MEDIUM | 4.3 | 0.3% | Aug 22, 2024 | The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the dup... |
| CVE-2024-7384 | HIGH | 8.8 | 1.0% | Aug 22, 2024 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v... |
| CVE-2024-5583 | MEDIUM | 5.4 | 0.2% | Aug 22, 2024 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre... |
| CVE-2024-39576 | HIGH | 8.8 | 0.2% | Aug 22, 2024 | Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low pri... |
| CVE-2024-43033 | HIGH | 8.8 | 1.0% | Aug 22, 2024 | JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via... |
| CVE-2024-42056 | MEDIUM | 6.5 | 0.2% | Aug 22, 2024 | Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials f... |
| CVE-2024-28987 | CRITICAL | 9.1 | 93.2% | Aug 21, 2024 | The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthe... |
| CVE-2024-8035 | MEDIUM | 4.3 | 0.3% | Aug 21, 2024 | Inappropriate implementation in Extensions in Google Chrome on Windows prior to 128.0.6613.84 allowed a remote attacker ... |
| CVE-2024-8034 | MEDIUM | 4.3 | 0.4% | Aug 21, 2024 | Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker... |
| CVE-2024-8033 | MEDIUM | 4.3 | 0.3% | Aug 21, 2024 | Inappropriate implementation in WebApp Installs in Google Chrome on Windows prior to 128.0.6613.84 allowed an attacker w... |
| CVE-2024-7981 | MEDIUM | 4.3 | 0.4% | Aug 21, 2024 | Inappropriate implementation in Views in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI sp... |
| CVE-2024-7980 | HIGH | 7.8 | 0.3% | Aug 21, 2024 | Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to... |
| CVE-2024-7979 | HIGH | 7.8 | 0.2% | Aug 21, 2024 | Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to... |
| CVE-2024-7978 | MEDIUM | 4.3 | 0.4% | Aug 21, 2024 | Insufficient policy enforcement in Data Transfer in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who c... |
| CVE-2024-7977 | HIGH | 7.8 | 0.3% | Aug 21, 2024 | Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to... |
| CVE-2024-7976 | MEDIUM | 4.3 | 0.4% | Aug 21, 2024 | Inappropriate implementation in FedCM in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI sp... |
| CVE-2024-7975 | MEDIUM | 4.3 | 0.4% | Aug 21, 2024 | Inappropriate implementation in Permissions in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform... |
| CVE-2024-7974 | HIGH | 8.8 | 0.5% | Aug 21, 2024 | Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now