2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48570 | HIGH | 7.5 | 0.5% | Oct 22, 2024 | Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports param... |
| CVE-2024-45518 | HIGH | 8.8 | 20.3% | Oct 22, 2024 | An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41,... |
| CVE-2024-48605 | HIGH | 7.8 | 0.5% | Oct 22, 2024 | An issue in Helakuru Desktop Application v1.1 allows a local attacker to execute arbitrary code via the lack of proper v... |
| CVE-2024-47819 | HIGH | 8.7 | 0.3% | Oct 22, 2024 | Umbraco, a free and open source .NET content management system, has a cross-site scripting vulnerability starting in ver... |
| CVE-2024-38002 | HIGH | 8.8 | 0.6% | Oct 22, 2024 | The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1... |
| CVE-2024-26273 | HIGH | 8.8 | 0.3% | Oct 22, 2024 | Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, an... |
| CVE-2024-26272 | HIGH | 8.8 | 0.3% | Oct 22, 2024 | Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, an... |
| CVE-2024-26271 | HIGH | 8.8 | 0.3% | Oct 22, 2024 | Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, a... |
| CVE-2024-10234 | HIGH | 7.3 | 0.6% | Oct 22, 2024 | A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. Th... |
| CVE-2024-9050 | HIGH | 7.8 | 0.5% | Oct 22, 2024 | A flaw was found in the libreswan client plugin for NetworkManager (NetkworkManager-libreswan), where it fails to proper... |
| CVE-2024-9987 | HIGH | 8.8 | 0.4% | Oct 22, 2024 | A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv func... |
| CVE-2024-35308 | HIGH | 8.8 | 0.6% | Oct 22, 2024 | A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. Thi... |
| CVE-2024-9627 | HIGH | 7.3 | 0.4% | Oct 22, 2024 | The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing... |
| CVE-2024-10002 | HIGH | 8.8 | 0.5% | Oct 22, 2024 | The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905. ... |
| CVE-2024-9677 | HIGH | 7.8 | 0.2% | Oct 22, 2024 | The insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version ... |
| CVE-2024-8901 | HIGH | 7.5 | 0.4% | Oct 22, 2024 | The AWS ALB Route Directive Adapter For Istio repo https://github.com/awslabs/aws-alb-route-directive-adapter-for-istio... |
| CVE-2024-10125 | HIGH | 7.5 | 0.3% | Oct 22, 2024 | The Amazon.ApplicationLoadBalancer.Identity.AspNetCore repo https://github.com/awslabs/aws-alb-identity-aspnetcore#vali... |
| CVE-2024-41714 | HIGH | 8.8 | 1.3% | Oct 21, 2024 | A vulnerability in the Web Interface component of Mitel MiCollab through 9.8 SP1 (9.8.1.5) and MiVoice Business Solution... |
| CVE-2024-30158 | HIGH | 7.2 | 0.4% | Oct 21, 2024 | A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attac... |
| CVE-2024-30157 | HIGH | 7.2 | 0.4% | Oct 21, 2024 | A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenti... |
| CVE-2024-50063 | HIGH | 7.8 | 0.2% | Oct 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: Prevent tail call between progs attached to di... |
| CVE-2024-50061 | HIGH | 7 | 0.2% | Oct 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: cdns: Fix use after free vulnerability... |
| CVE-2024-50059 | HIGH | 7 | 0.2% | Oct 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: ntb: ntb_hw_switchtec: Fix use after free vulnerabi... |
| CVE-2024-50055 | HIGH | 7.8 | 0.3% | Oct 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: driver core: bus: Fix double free in driver API bus... |
| CVE-2024-50047 | HIGH | 7.8 | 0.2% | Oct 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF in async decryption Doing an ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now