2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7575 | CRITICAL | 9.8 | 0.7% | Sep 25, 2024 | In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through im... |
| CVE-2024-4657 | CRITICAL | 9.3 | 0.4% | Sep 25, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Soft... |
| CVE-2024-6593 | CRITICAL | 9.1 | 0.5% | Sep 25, 2024 | Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows ... |
| CVE-2024-6592 | CRITICAL | 9.1 | 1.0% | Sep 25, 2024 | An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (ak... |
| CVE-2024-8275 | CRITICAL | 9.8 | 49.7% | Sep 25, 2024 | The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_... |
| CVE-2024-8485 | CRITICAL | 9.8 | 0.6% | Sep 25, 2024 | The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versio... |
| CVE-2024-9142 | CRITICAL | 9.8 | 0.4% | Sep 25, 2024 | External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Com... |
| CVE-2024-8940 | CRITICAL | 9.8 | 0.5% | Sep 25, 2024 | Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptca... |
| CVE-2024-8878 | CRITICAL | 9.8 | 1.3% | Sep 25, 2024 | The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin pa... |
| CVE-2024-8877 | CRITICAL | 9.8 | 77.3% | Sep 25, 2024 | Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only li... |
| CVE-2024-8436 | CRITICAL | 9.9 | 0.5% | Sep 25, 2024 | The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId... |
| CVE-2024-46957 | CRITICAL | 9.8 | 0.6% | Sep 25, 2024 | Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because... |
| CVE-2024-46612 | CRITICAL | 9.8 | 0.6% | Sep 25, 2024 | IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication... |
| CVE-2024-45066 | CRITICAL | 9.8 | 0.8% | Sep 25, 2024 | A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject a... |
| CVE-2024-43693 | CRITICAL | 9.8 | 0.8% | Sep 25, 2024 | A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inj... |
| CVE-2024-43692 | CRITICAL | 9.8 | 0.5% | Sep 25, 2024 | An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting t... |
| CVE-2024-43423 | CRITICAL | 9.8 | 0.7% | Sep 25, 2024 | The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that... |
| CVE-2024-42797 | CRITICAL | 9.8 | 0.5% | Sep 25, 2024 | An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Managem... |
| CVE-2024-42507 | CRITICAL | 9.8 | 1.4% | Sep 25, 2024 | Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by s... |
| CVE-2024-42506 | CRITICAL | 9.8 | 1.4% | Sep 25, 2024 | Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by s... |
| CVE-2024-42505 | CRITICAL | 9.8 | 1.5% | Sep 25, 2024 | Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by s... |
| CVE-2024-8791 | CRITICAL | 9.8 | 0.7% | Sep 24, 2024 | The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnera... |
| CVE-2024-8671 | CRITICAL | 9.1 | 1.0% | Sep 24, 2024 | The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insuffi... |
| CVE-2024-8624 | CRITICAL | 9.9 | 0.5% | Sep 24, 2024 | The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' attrib... |
| CVE-2024-7024 | CRITICAL | 9.6 | 0.3% | Sep 23, 2024 | Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perf... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now