2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7272 | HIGH | 8.8 | 1.1% | Aug 12, 2024 | A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5. This affects the function fill_audio... |
| CVE-2024-7006 | HIGH | 7.5 | 1.5% | Aug 12, 2024 | A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger me... |
| CVE-2024-6760 | HIGH | 7.5 | 0.7% | Aug 12, 2024 | A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it sh... |
| CVE-2024-6759 | MEDIUM | 5.3 | 0.7% | Aug 12, 2024 | When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separa... |
| CVE-2024-6758 | MEDIUM | 6.5 | 0.4% | Aug 12, 2024 | Improper Privilege Management in Sprecher Automation SPRECON-E below version 8.71j allows a remote attacker with low pri... |
| CVE-2024-6692 | LOW | 3.1 | 0.4% | Aug 12, 2024 | The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPr... |
| CVE-2024-6691 | MEDIUM | 4 | 0.3% | Aug 12, 2024 | The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPr... |
| CVE-2024-6684 | CRITICAL | 9.9 | 0.6% | Aug 12, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom Nova Panel N7 allows Au... |
| CVE-2024-6640 | MEDIUM | 6.3 | 0.5% | Aug 12, 2024 | In ICMPv6 Neighbor Discovery (ND), the ID is always 0. When pf is configured to allow ND and block incoming Echo Reques... |
| CVE-2024-6562 | MEDIUM | 5.3 | 0.6% | Aug 12, 2024 | The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all ver... |
| CVE-2024-6158 | MEDIUM | 4.8 | 0.4% | Aug 12, 2024 | The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4... |
| CVE-2024-6136 | MEDIUM | 5.4 | 0.2% | Aug 12, 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could all... |
| CVE-2024-6134 | MEDIUM | 5.4 | 0.4% | Aug 12, 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputtin... |
| CVE-2024-6133 | MEDIUM | 6.5 | 0.4% | Aug 12, 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputtin... |
| CVE-2024-5801 | MEDIUM | 5.3 | 0.3% | Aug 12, 2024 | Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise ... |
| CVE-2024-5800 | HIGH | 7.5 | 0.3% | Aug 12, 2024 | Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before... |
| CVE-2024-5651 | HIGH | 8.8 | 1.4% | Aug 12, 2024 | A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) pr... |
| CVE-2024-5527 | HIGH | 8.8 | 4.7% | Aug 12, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing co... |
| CVE-2024-5487 | HIGH | 8.8 | 4.7% | Aug 12, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface a... |
| CVE-2024-5445 | LOW | 3.8 | 0.3% | Aug 12, 2024 | Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS cert... |
| CVE-2024-4360 | MEDIUM | 5.4 | 0.4% | Aug 12, 2024 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W... |
| CVE-2024-4359 | MEDIUM | 6.5 | 0.5% | Aug 12, 2024 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W... |
| CVE-2024-4350 | MEDIUM | 4.8 | 0.5% | Aug 12, 2024 | Concrete CMS versions 9.0.0 to 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer when user input is s... |
| CVE-2024-43168 | MEDIUM | 4.8 | 0.3% | Aug 12, 2024 | DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, ... |
| CVE-2024-43167 | LOW | 2.8 | 0.4% | Aug 12, 2024 | DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now