2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6500 | CRITICAL | 10 | 1.0% | Aug 17, 2024 | The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion ... |
| CVE-2024-43042 | CRITICAL | 9.8 | 0.6% | Aug 16, 2024 | Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack. |
| CVE-2024-42850 | CRITICAL | 9.8 | 1.5% | Aug 16, 2024 | An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity ... |
| CVE-2024-42639 | CRITICAL | 9.8 | 0.6% | Aug 16, 2024 | H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as roo... |
| CVE-2024-42638 | CRITICAL | 9.8 | 0.6% | Aug 16, 2024 | H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attack... |
| CVE-2024-42637 | CRITICAL | 9.8 | 0.6% | Aug 16, 2024 | H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attacker... |
| CVE-2024-42634 | CRITICAL | 9.8 | 2.2% | Aug 16, 2024 | A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, ... |
| CVE-2024-42466 | CRITICAL | 9.8 | 0.7% | Aug 16, 2024 | Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager a... |
| CVE-2024-42465 | CRITICAL | 9.8 | 0.5% | Aug 16, 2024 | Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager a... |
| CVE-2024-42462 | CRITICAL | 9.8 | 0.5% | Aug 16, 2024 | Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This i... |
| CVE-2024-6460 | CRITICAL | 9.8 | 4.8% | Aug 16, 2024 | The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parame... |
| CVE-2024-7851 | CRITICAL | 9.8 | 0.6% | Aug 16, 2024 | A vulnerability has been found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This vul... |
| CVE-2024-7839 | CRITICAL | 9.8 | 0.6% | Aug 15, 2024 | A vulnerability classified as critical has been found in itsourcecode Billing System 1.0. This affects an unknown part o... |
| CVE-2024-43366 | CRITICAL | 9.1 | 0.5% | Aug 15, 2024 | zkvyper is a Vyper compiler. Starting in version 1.3.12 and prior to version 1.5.3, since LLL IR has no Turing-incomplet... |
| CVE-2024-7838 | CRITICAL | 9.8 | 0.6% | Aug 15, 2024 | A vulnerability was found in itsourcecode Online Food Ordering System 1.0. It has been rated as critical. Affected by th... |
| CVE-2024-42757 | CRITICAL | 9.8 | 1.3% | Aug 15, 2024 | Command injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via ... |
| CVE-2024-42472 | CRITICAL | 10 | 1.3% | Aug 15, 2024 | Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious ... |
| CVE-2024-27730 | CRITICAL | 9.8 | 0.8% | Aug 15, 2024 | Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and e... |
| CVE-2024-23168 | CRITICAL | 9.8 | 0.4% | Aug 15, 2024 | Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSoc... |
| CVE-2024-42978 | CRITICAL | 9.8 | 1.2% | Aug 15, 2024 | An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary co... |
| CVE-2024-42967 | CRITICAL | 9.8 | 0.6% | Aug 15, 2024 | Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration fil... |
| CVE-2024-42966 | CRITICAL | 9.8 | 0.6% | Aug 15, 2024 | Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration fi... |
| CVE-2024-42947 | CRITICAL | 9.8 | 1.0% | Aug 15, 2024 | An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary... |
| CVE-2024-42843 | CRITICAL | 9.8 | 0.6% | Aug 15, 2024 | Projectworlds Online Examination System v1.0 is vulnerable to SQL Injection via the subject parameter in feed.php. |
| CVE-2024-7833 | CRITICAL | 9.8 | 4.7% | Aug 15, 2024 | A vulnerability was found in D-Link DI-8100 16.07. It has been classified as critical. This affects the function upgrade... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now