2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45771 | CRITICAL | 9.8 | 0.5% | Sep 6, 2024 | RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin... |
| CVE-2024-44839 | CRITICAL | 9.8 | 0.5% | Sep 6, 2024 | RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article.... |
| CVE-2024-44838 | CRITICAL | 9.8 | 0.5% | Sep 6, 2024 | RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin... |
| CVE-2024-8517 | CRITICAL | 9.8 | 94.6% | Sep 6, 2024 | SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacke... |
| CVE-2024-45758 | CRITICAL | 9.1 | 0.9% | Sep 6, 2024 | H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file r... |
| CVE-2024-44402 | CRITICAL | 9.8 | 3.1% | Sep 6, 2024 | D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm. |
| CVE-2024-44401 | CRITICAL | 9.8 | 2.9% | Sep 6, 2024 | D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file |
| CVE-2024-7493 | CRITICAL | 9.8 | 0.6% | Sep 6, 2024 | The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.... |
| CVE-2024-8292 | CRITICAL | 9.8 | 0.6% | Sep 6, 2024 | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/accoun... |
| CVE-2024-8395 | CRITICAL | 9.8 | 0.7% | Sep 5, 2024 | FlyCASS CASS and KCM systems did not correctly filter SQL queries, which made them vulnerable to attack by outside atta... |
| CVE-2024-45159 | CRITICAL | 9.8 | 0.4% | Sep 5, 2024 | An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the... |
| CVE-2024-45158 | CRITICAL | 9.8 | 0.7% | Sep 5, 2024 | An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_... |
| CVE-2024-44727 | CRITICAL | 9.8 | 0.5% | Sep 5, 2024 | Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/lo... |
| CVE-2024-24759 | CRITICAL | 9.1 | 4.9% | Sep 5, 2024 | MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat ac... |
| CVE-2024-42885 | CRITICAL | 9.1 | 0.6% | Sep 5, 2024 | SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id param... |
| CVE-2024-43102 | CRITICAL | 10 | 0.7% | Sep 5, 2024 | Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM... |
| CVE-2024-8416 | CRITICAL | 9.8 | 0.6% | Sep 4, 2024 | A vulnerability was found in SourceCodester Food Ordering Management System 1.0. It has been classified as critical. Thi... |
| CVE-2024-8415 | CRITICAL | 9.8 | 0.6% | Sep 4, 2024 | A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as critical. Affected by ... |
| CVE-2024-20439 | CRITICAL | 9.8 | 92.0% | Sep 4, 2024 | A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an a... |
| CVE-2024-45076 | CRITICAL | 9.9 | 0.5% | Sep 4, 2024 | IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be ... |
| CVE-2024-44808 | CRITICAL | 9.8 | 0.9% | Sep 4, 2024 | An issue in Vypor Attack API System v.1.0 allows a remote attacker to execute arbitrary code via the user GET parameter. |
| CVE-2024-7078 | CRITICAL | 9.8 | 0.5% | Sep 4, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics... |
| CVE-2024-7076 | CRITICAL | 9.8 | 0.5% | Sep 4, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics... |
| CVE-2024-8408 | CRITICAL | 9.8 | 0.8% | Sep 4, 2024 | A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the functio... |
| CVE-2024-7923 | CRITICAL | 9.8 | 0.8% | Sep 4, 2024 | An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now