2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9318 | CRITICAL | 9.8 | 0.5% | Sep 28, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Advocate Office Management System 1.... |
| CVE-2024-9296 | CRITICAL | 9.8 | 0.6% | Sep 28, 2024 | A vulnerability was found in SourceCodester Advocate Office Management System 1.0. It has been classified as critical. A... |
| CVE-2024-9295 | CRITICAL | 9.8 | 0.6% | Sep 28, 2024 | A vulnerability was found in SourceCodester Advocate Office Management System 1.0 and classified as critical. This issue... |
| CVE-2024-8353 | CRITICAL | 9.8 | 29.1% | Sep 28, 2024 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all ... |
| CVE-2024-46256 | CRITICAL | 9.8 | 3.0% | Sep 27, 2024 | A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add... |
| CVE-2024-8630 | CRITICAL | 9.8 | 0.6% | Sep 27, 2024 | Alisonic Sibylla devices are vulnerable to SQL injection attacks, which could allow complete access to the database. |
| CVE-2024-8310 | CRITICAL | 9.8 | 0.7% | Sep 27, 2024 | OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full... |
| CVE-2024-6981 | CRITICAL | 9.8 | 0.6% | Sep 27, 2024 | OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without pro... |
| CVE-2024-46367 | CRITICAL | 9.6 | 0.5% | Sep 27, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary... |
| CVE-2024-22170 | CRITICAL | 9.2 | 0.5% | Sep 27, 2024 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-s... |
| CVE-2024-47070 | CRITICAL | 9 | 0.5% | Sep 27, 2024 | authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 al... |
| CVE-2024-3373 | CRITICAL | 9.2 | 0.4% | Sep 27, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RSM Design Website... |
| CVE-2024-9280 | CRITICAL | 9.8 | 0.5% | Sep 27, 2024 | A vulnerability has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff and classified as c... |
| CVE-2024-8643 | CRITICAL | 9.8 | 0.4% | Sep 27, 2024 | Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking. This issue affects Va... |
| CVE-2024-8607 | CRITICAL | 9.8 | 0.5% | Sep 27, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic Software V... |
| CVE-2024-47175 | CRITICAL | 9.8 | 73.1% | Sep 26, 2024 | CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libpp... |
| CVE-2024-46628 | CRITICAL | 9.8 | 11.0% | Sep 26, 2024 | Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbP... |
| CVE-2024-9166 | CRITICAL | 9.3 | 1.5% | Sep 26, 2024 | The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilit... |
| CVE-2024-46627 | CRITICAL | 9.1 | 3.9% | Sep 26, 2024 | Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests. |
| CVE-2024-7108 | CRITICAL | 9.8 | 0.3% | Sep 26, 2024 | Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality ... |
| CVE-2024-7781 | CRITICAL | 9.8 | 1.0% | Sep 26, 2024 | The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7... |
| CVE-2024-7772 | CRITICAL | 9.8 | 1.5% | Sep 26, 2024 | The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation... |
| CVE-2024-20510 | CRITICAL | 9.3 | 0.3% | Sep 25, 2024 | A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could ... |
| CVE-2024-47078 | CRITICAL | 9.8 | 0.5% | Sep 25, 2024 | Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an interne... |
| CVE-2024-7576 | CRITICAL | 9.8 | 0.5% | Sep 25, 2024 | In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an in... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now