2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6813 | HIGH | 8.8 | 1.9% | Aug 21, 2024 | NETGEAR ProSAFE Network Management System getSortString SQL Injection Remote Code Execution Vulnerability. This vulnerab... |
| CVE-2024-6812 | HIGH | 7.8 | 0.5% | Aug 21, 2024 | IrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote att... |
| CVE-2024-6811 | HIGH | 7.8 | 0.5% | Aug 21, 2024 | IrfanView WSQ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote att... |
| CVE-2024-43411 | LOW | 3.1 | 0.4% | Aug 21, 2024 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A theoretical vulnerability has been identified in... |
| CVE-2024-43410 | HIGH | 7.5 | 0.9% | Aug 21, 2024 | Russh is a Rust SSH client & server library. Allocating an untrusted amount of memory allows any unauthenticated user to... |
| CVE-2024-43027 | HIGH | 8 | 1.3% | Aug 21, 2024 | DrayTek Vigor 3900 before v1.5.1.5_Beta, DrayTek Vigor 2960 before v1.5.1.5_Beta and DrayTek Vigor 300B before v1.5.1.5_... |
| CVE-2024-41937 | MEDIUM | 6.1 | 1.8% | Aug 21, 2024 | Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execut... |
| CVE-2024-39344 | HIGH | 8.1 | 0.5% | Aug 21, 2024 | An issue was discovered in the Docusign API package 8.142.14 for Salesforce. The Apttus_DocuApi__DocusignAuthentication_... |
| CVE-2024-21690 | HIGH | 8.2 | 0.7% | Aug 21, 2024 | This High severity Reflected XSS and CSRF (Cross-Site Request Forgery) vulnerability was introduced in versions 7.19.0, ... |
| CVE-2024-43407 | MEDIUM | 6.1 | 0.4% | Aug 21, 2024 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has been discovered in C... |
| CVE-2024-43371 | MEDIUM | 6.5 | 0.3% | Aug 21, 2024 | CKAN is an open-source data management system for powering data hubs and data portals. There are a number of CKAN plugin... |
| CVE-2024-41675 | MEDIUM | 6.1 | 0.4% | Aug 21, 2024 | CKAN is an open-source data management system for powering data hubs and data portals. The Datatables view plugin did no... |
| CVE-2024-41674 | MEDIUM | 5.3 | 0.4% | Aug 21, 2024 | CKAN is an open-source data management system for powering data hubs and data portals. If there were connection issues w... |
| CVE-2024-8007 | HIGH | 8.1 | 0.4% | Aug 21, 2024 | A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vuln... |
| CVE-2024-7885 | HIGH | 7.5 | 2.6% | Aug 21, 2024 | A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across ... |
| CVE-2024-28000 | CRITICAL | 9.8 | 67.9% | Aug 21, 2024 | Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affect... |
| CVE-2024-37008 | HIGH | 7.8 | 0.2% | Aug 21, 2024 | A maliciously crafted DWG file, when parsed in Revit, can force a stack-based buffer overflow. A malicious actor can lev... |
| CVE-2024-7757 | — | — | — | Aug 21, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-5335 | CRITICAL | 9.8 | 0.9% | Aug 21, 2024 | The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Produc... |
| CVE-2024-6339 | MEDIUM | 6.1 | 0.4% | Aug 21, 2024 | The Phlox PRO theme for WordPress is vulnerable to Reflected Cross-Site Scripting via search parameters in all versions ... |
| CVE-2024-7998 | LOW | 2.6 | 0.2% | Aug 21, 2024 | In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them usin... |
| CVE-2024-7854 | CRITICAL | 9.8 | 4.3% | Aug 21, 2024 | The Woo Inquiry plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 0.1 due to ins... |
| CVE-2024-7651 | HIGH | 7.5 | 0.4% | Aug 21, 2024 | The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to limited SQL Injec... |
| CVE-2024-7647 | MEDIUM | 6.1 | 0.2% | Aug 21, 2024 | The OTA Sync Booking Engine Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2024-7629 | MEDIUM | 5.4 | 0.3% | Aug 21, 2024 | The Responsive video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's video settings f... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now