2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7257 | CRITICAL | 9.8 | 1.0% | Aug 3, 2024 | The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to mis... |
| CVE-2024-7031 | HIGH | 8.8 | 0.6% | Aug 3, 2024 | The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... |
| CVE-2024-7291 | HIGH | 7.2 | 0.5% | Aug 3, 2024 | The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.... |
| CVE-2024-6477 | HIGH | 7.5 | 0.6% | Aug 3, 2024 | The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could all... |
| CVE-2024-6390 | MEDIUM | 5.9 | 0.3% | Aug 3, 2024 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz ... |
| CVE-2024-7319 | MEDIUM | 5 | 0.4% | Aug 2, 2024 | An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through... |
| CVE-2024-3056 | HIGH | 7.7 | 0.5% | Aug 2, 2024 | A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configur... |
| CVE-2024-38891 | HIGH | 7.5 | 0.5% | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows... |
| CVE-2024-38887 | CRITICAL | 9.8 | 1.7% | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows... |
| CVE-2024-42349 | MEDIUM | 5.3 | 0.6% | Aug 2, 2024 | FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.4 and earlier can leak authorize... |
| CVE-2024-42348 | HIGH | 8.6 | 0.6% | Aug 2, 2024 | FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and passw... |
| CVE-2024-38889 | CRITICAL | 9.8 | 0.9% | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows... |
| CVE-2024-38888 | MEDIUM | 6.8 | 0.2% | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows... |
| CVE-2024-28298 | HIGH | 8.8 | 0.5% | Aug 2, 2024 | SQL injection vulnerability in BM SOFT BMPlanning 1.0.0.1 allows authenticated users to execute arbitrary SQL commands v... |
| CVE-2024-28297 | HIGH | 7.5 | 0.4% | Aug 2, 2024 | SQL injection vulnerability in AzureSoft MyHorus 4.3.5 allows authenticated users to execute arbitrary SQL commands via ... |
| CVE-2024-22169 | HIGH | 7.1 | 0.3% | Aug 2, 2024 | WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow c... |
| CVE-2024-38886 | CRITICAL | 9.8 | 0.8% | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows... |
| CVE-2024-38885 | HIGH | 7.5 | 0.5% | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows... |
| CVE-2024-38884 | HIGH | 7.8 | 0.2% | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows... |
| CVE-2024-38883 | CRITICAL | 9.1 | 0.4% | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows... |
| CVE-2024-38882 | CRITICAL | 9.8 | 0.9% | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows... |
| CVE-2024-38881 | HIGH | 7.5 | 0.5% | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows... |
| CVE-2024-33896 | HIGH | 7.2 | 4.0% | Aug 2, 2024 | Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due... |
| CVE-2024-33895 | MEDIUM | 6.6 | 0.5% | Aug 2, 2024 | Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the conf... |
| CVE-2024-33894 | HIGH | 8.8 | 0.8% | Aug 2, 2024 | Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now