2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42995 | HIGH | 8.3 | 0.4% | Aug 16, 2024 | VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migr... |
| CVE-2024-42994 | HIGH | 7.2 | 0.5% | Aug 16, 2024 | VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection... |
| CVE-2024-42634 | CRITICAL | 9.8 | 2.2% | Aug 16, 2024 | A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, ... |
| CVE-2024-6098 | MEDIUM | 5.9 | 0.4% | Aug 16, 2024 | When performing an online tag generation to devices which communicate using the ControlLogix protocol, a machine-in-the... |
| CVE-2024-6004 | MEDIUM | 6.5 | 0.3% | Aug 16, 2024 | A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a... |
| CVE-2024-5210 | MEDIUM | 6.5 | 0.3% | Aug 16, 2024 | A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a... |
| CVE-2024-5209 | MEDIUM | 6.5 | 0.3% | Aug 16, 2024 | A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a... |
| CVE-2024-4782 | MEDIUM | 6.5 | 0.3% | Aug 16, 2024 | A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a... |
| CVE-2024-4781 | MEDIUM | 6.5 | 0.3% | Aug 16, 2024 | A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a... |
| CVE-2024-4763 | HIGH | 7.8 | 0.2% | Aug 16, 2024 | An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display... |
| CVE-2024-43810 | MEDIUM | 5.4 | 0.3% | Aug 16, 2024 | In JetBrains TeamCity before 2024.07.1 reflected XSS was possible in the AWS Core plugin |
| CVE-2024-43809 | MEDIUM | 6.1 | 0.3% | Aug 16, 2024 | In JetBrains TeamCity before 2024.07.1 reflected XSS was possible on the agentPushPreset page |
| CVE-2024-43808 | MEDIUM | 5.4 | 0.2% | Aug 16, 2024 | In JetBrains TeamCity before 2024.07.1 self XSS was possible in the HashiCorp Vault plugin |
| CVE-2024-43807 | MEDIUM | 5.4 | 0.3% | Aug 16, 2024 | In JetBrains TeamCity before 2024.07.1 multiple stored XSS was possible on Clouds page |
| CVE-2024-43381 | MEDIUM | 5.4 | 0.4% | Aug 16, 2024 | reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Store... |
| CVE-2024-42486 | HIGH | 7.2 | 0.6% | Aug 16, 2024 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. In versions on the 1.15.x bra... |
| CVE-2024-2175 | HIGH | 7.8 | 0.2% | Aug 16, 2024 | An insecure permissions vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Di... |
| CVE-2024-7145 | HIGH | 8.8 | 0.9% | Aug 16, 2024 | The JetElements plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.20 ... |
| CVE-2024-7144 | MEDIUM | 5.4 | 0.3% | Aug 16, 2024 | The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'slide_id' parameters... |
| CVE-2024-42466 | CRITICAL | 9.8 | 0.7% | Aug 16, 2024 | Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager a... |
| CVE-2024-42465 | CRITICAL | 9.8 | 0.5% | Aug 16, 2024 | Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager a... |
| CVE-2024-42464 | MEDIUM | 6.5 | 0.3% | Aug 16, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Uti... |
| CVE-2024-42463 | MEDIUM | 6.5 | 0.4% | Aug 16, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Uti... |
| CVE-2024-42462 | CRITICAL | 9.8 | 0.5% | Aug 16, 2024 | Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This i... |
| CVE-2024-7147 | MEDIUM | 6.4 | 0.3% | Aug 16, 2024 | The JetBlocks for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple placeholder p... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now