2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42266 | MEDIUM | 5.5 | 0.2% | Aug 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: btrfs: make cow_file_range_inline() honor locked_pa... |
| CVE-2024-42265 | MEDIUM | 5.5 | 0.3% | Aug 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: protect the fetch of ->fd[fd] in do_dup2() from mis... |
| CVE-2024-42264 | HIGH | 7.1 | 0.2% | Aug 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Prevent out of bounds access in performanc... |
| CVE-2024-42263 | MEDIUM | 5.5 | 0.2% | Aug 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix potential memory leak in the timestamp... |
| CVE-2024-42262 | MEDIUM | 5.5 | 0.2% | Aug 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix potential memory leak in the performan... |
| CVE-2024-42261 | MEDIUM | 5.5 | 0.2% | Aug 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Validate passed in drm syncobj handles in ... |
| CVE-2024-42260 | MEDIUM | 5.5 | 0.2% | Aug 17, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Validate passed in drm syncobj handles in ... |
| CVE-2024-6459 | CRITICAL | 9.8 | 1.0% | Aug 17, 2024 | The News Element Elementor Blog Magazine WordPress plugin before 1.0.6 is vulnerable to Local File Inclusion via the tem... |
| CVE-2024-6500 | CRITICAL | 10 | 1.0% | Aug 17, 2024 | The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion ... |
| CVE-2024-7886 | HIGH | 8.5 | 0.2% | Aug 16, 2024 | A vulnerability has been found in Scooter Software Beyond Compare up to 3.3.5.15075 and classified as critical. Affected... |
| CVE-2024-43395 | HIGH | 8.2 | 0.4% | Aug 16, 2024 | CraftOS-PC 2 is a rewrite of the desktop port of CraftOS from the popular Minecraft mod ComputerCraft using C++ and a mo... |
| CVE-2024-43472 | HIGH | 8.3 | 0.4% | Aug 16, 2024 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2024-43042 | CRITICAL | 9.8 | 0.6% | Aug 16, 2024 | Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack. |
| CVE-2024-43011 | MEDIUM | 4.9 | 0.7% | Aug 16, 2024 | An arbitrary file deletion vulnerability exists in the admin/del.php file at line 62 in ZZCMS 2023 and earlier. Due to i... |
| CVE-2024-43009 | MEDIUM | 4.7 | 0.4% | Aug 16, 2024 | A reflected cross-site scripting (XSS) vulnerability exists in user/login.php at line 24 in ZZCMS 2023 and earlier. The ... |
| CVE-2024-43006 | MEDIUM | 5.4 | 0.2% | Aug 16, 2024 | A stored cross-site scripting (XSS) vulnerability exists in ZZCMS2023 in the ask/show.php file at line 21. An attacker c... |
| CVE-2024-43005 | MEDIUM | 4.7 | 0.3% | Aug 16, 2024 | A reflected cross-site scripting (XSS) vulnerability in the component dl_liuyan_save.php of ZZCMS v2023 allows attackers... |
| CVE-2024-42850 | CRITICAL | 9.8 | 1.5% | Aug 16, 2024 | An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity ... |
| CVE-2024-42849 | MEDIUM | 6.5 | 1.3% | Aug 16, 2024 | An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change f... |
| CVE-2024-7646 | HIGH | 8.8 | 26.0% | Aug 16, 2024 | A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `netwo... |
| CVE-2024-42758 | MEDIUM | 5.4 | 0.7% | Aug 16, 2024 | A Cross-site Scripting (XSS) vulnerability exists in version v2024-01-05 of the indexmenu plugin when is used and enable... |
| CVE-2024-42639 | CRITICAL | 9.8 | 0.6% | Aug 16, 2024 | H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as roo... |
| CVE-2024-42638 | CRITICAL | 9.8 | 0.6% | Aug 16, 2024 | H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attack... |
| CVE-2024-42637 | CRITICAL | 9.8 | 0.6% | Aug 16, 2024 | H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attacker... |
| CVE-2024-25837 | MEDIUM | 5.4 | 0.2% | Aug 16, 2024 | A stored cross-site scripting (XSS) vulnerability in October CMS Bloghub Plugin v1.3.8 and lower allows attackers to exe... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now