2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7012 | CRITICAL | 9.8 | 0.8% | Sep 4, 2024 | An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to... |
| CVE-2024-44400 | CRITICAL | 9.8 | 14.1% | Sep 4, 2024 | A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgr... |
| CVE-2024-8289 | CRITICAL | 9.8 | 1.3% | Sep 4, 2024 | The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to privi... |
| CVE-2024-45507 | CRITICAL | 9.8 | 93.2% | Sep 4, 2024 | Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OF... |
| CVE-2024-6926 | CRITICAL | 9.8 | 3.3% | Sep 4, 2024 | The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQ... |
| CVE-2024-34657 | CRITICAL | 9.8 | 0.6% | Sep 4, 2024 | Stack-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows remote attackers to execute arbitrary... |
| CVE-2024-7950 | CRITICAL | 9.8 | 1.2% | Sep 4, 2024 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to... |
| CVE-2024-45443 | CRITICAL | 9.1 | 0.5% | Sep 4, 2024 | Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect a... |
| CVE-2024-44809 | CRITICAL | 9.8 | 0.8% | Sep 3, 2024 | A remote code execution (RCE) vulnerability exists in the Pi Camera project, version 1.0, maintained by RECANTHA. The is... |
| CVE-2024-41433 | CRITICAL | 9.8 | 0.6% | Sep 3, 2024 | PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This... |
| CVE-2024-45390 | CRITICAL | 9.8 | 0.4% | Sep 3, 2024 | @blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within... |
| CVE-2024-45307 | CRITICAL | 9.8 | 0.3% | Sep 3, 2024 | SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in version... |
| CVE-2024-7345 | CRITICAL | 9.6 | 0.6% | Sep 3, 2024 | Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injectio... |
| CVE-2024-4259 | CRITICAL | 9.8 | 0.5% | Sep 3, 2024 | Missing Authorization vulnerability in SAMPAŞ Holding AKOS (AkosCepVatandasService), SAMPAŞ Holding AKOS (TahsilatServic... |
| CVE-2024-8389 | CRITICAL | 9.8 | 0.5% | Sep 3, 2024 | Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2024-8387 | CRITICAL | 9.8 | 0.6% | Sep 3, 2024 | Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence ... |
| CVE-2024-8385 | CRITICAL | 9.8 | 0.6% | Sep 3, 2024 | A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusi... |
| CVE-2024-8384 | CRITICAL | 9.8 | 0.7% | Sep 3, 2024 | The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right ... |
| CVE-2024-8381 | CRITICAL | 9.8 | 4.4% | Sep 3, 2024 | A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as t... |
| CVE-2024-44921 | CRITICAL | 9.8 | 0.6% | Sep 3, 2024 | SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac... |
| CVE-2024-7261 | CRITICAL | 9.8 | 11.3% | Sep 3, 2024 | The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware... |
| CVE-2024-8380 | CRITICAL | 9.8 | 0.6% | Sep 3, 2024 | A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been rated as critical. This ... |
| CVE-2024-45623 | CRITICAL | 9.8 | 0.9% | Sep 2, 2024 | D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer... |
| CVE-2024-45622 | CRITICAL | 9.8 | 36.0% | Sep 2, 2024 | ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for A... |
| CVE-2024-6919 | CRITICAL | 9.8 | 0.4% | Sep 2, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NAC Telecommunicat... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now