2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43812 | HIGH | 8.6 | 0.2% | Oct 22, 2024 | Kieback & Peter's DDC4000 series has an insufficiently protected credentials vulnerability, which may allow an unauthent... |
| CVE-2024-42643 | HIGH | 7.5 | 0.6% | Oct 22, 2024 | Integer Overflow in fast_ping.c in SmartDNS Release46 allows remote attackers to cause a Denial of Service via misaligne... |
| CVE-2024-31029 | HIGH | 8.2 | 0.5% | Oct 22, 2024 | An issue in the server_handle_regular function of the test_coap_server.c file within the FreeCoAP project allows remote ... |
| CVE-2024-10231 | HIGH | 8.8 | 0.5% | Oct 22, 2024 | Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2024-10230 | HIGH | 8.8 | 0.6% | Oct 22, 2024 | Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2024-10229 | HIGH | 8.1 | 0.5% | Oct 22, 2024 | Inappropriate implementation in Extensions in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to bypass s... |
| CVE-2024-48903 | HIGH | 7.8 | 0.7% | Oct 22, 2024 | An improper access control vulnerability in Trend Micro Deep Security Agent 20 could allow a local attacker to escalate ... |
| CVE-2024-45334 | HIGH | 7.8 | 0.1% | Oct 22, 2024 | Trend Micro Antivirus One versions 3.10.4 and below (Consumer) is vulnerable to an Arbitrary Configuration Update that c... |
| CVE-2024-41183 | HIGH | 7.8 | 1.0% | Oct 22, 2024 | Trend Micro VPN, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite under specific conditions that ... |
| CVE-2024-39753 | HIGH | 7.5 | 2.0% | Oct 22, 2024 | An modOSCE SQL Injection vulnerability in Trend Micro Apex One could allow a remote attacker to execute arbitrary code o... |
| CVE-2024-9287 | HIGH | 7.8 | 0.6% | Oct 22, 2024 | A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual en... |
| CVE-2024-48570 | HIGH | 7.5 | 0.5% | Oct 22, 2024 | Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports param... |
| CVE-2024-45518 | HIGH | 8.8 | 20.3% | Oct 22, 2024 | An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41,... |
| CVE-2024-48605 | HIGH | 7.8 | 0.5% | Oct 22, 2024 | An issue in Helakuru Desktop Application v1.1 allows a local attacker to execute arbitrary code via the lack of proper v... |
| CVE-2024-47819 | HIGH | 8.7 | 0.3% | Oct 22, 2024 | Umbraco, a free and open source .NET content management system, has a cross-site scripting vulnerability starting in ver... |
| CVE-2024-38002 | HIGH | 8.8 | 0.6% | Oct 22, 2024 | The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1... |
| CVE-2024-26273 | HIGH | 8.8 | 0.3% | Oct 22, 2024 | Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, an... |
| CVE-2024-26272 | HIGH | 8.8 | 0.3% | Oct 22, 2024 | Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, an... |
| CVE-2024-26271 | HIGH | 8.8 | 0.3% | Oct 22, 2024 | Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, a... |
| CVE-2024-10234 | HIGH | 7.3 | 0.6% | Oct 22, 2024 | A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. Th... |
| CVE-2024-9050 | HIGH | 7.8 | 0.5% | Oct 22, 2024 | A flaw was found in the libreswan client plugin for NetworkManager (NetkworkManager-libreswan), where it fails to proper... |
| CVE-2024-9987 | HIGH | 8.8 | 0.4% | Oct 22, 2024 | A post-authentication SQL Injection vulnerability within the filters parameter of the extensions/agents_modules_csv func... |
| CVE-2024-35308 | HIGH | 8.8 | 0.6% | Oct 22, 2024 | A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. Thi... |
| CVE-2024-9627 | HIGH | 7.3 | 0.4% | Oct 22, 2024 | The TeploBot - Telegram Bot for WP plugin for WordPress is vulnerable to sensitive information disclosure due to missing... |
| CVE-2024-10002 | HIGH | 8.8 | 0.5% | Oct 22, 2024 | The Rover IDX plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0.0.2905. ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now