2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4184 | HIGH | 8 | 0.4% | Oct 16, 2024 | Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD ... |
| CVE-2024-38814 | HIGH | 8.8 | 14.6% | Oct 16, 2024 | An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated ... |
| CVE-2024-20463 | HIGH | 7.1 | 0.3% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al... |
| CVE-2024-20459 | HIGH | 7.2 | 0.7% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Multiplatform Series Analog Telephone Adapter fir... |
| CVE-2024-20458 | HIGH | 8.2 | 0.7% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al... |
| CVE-2024-20420 | HIGH | 8.8 | 0.4% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al... |
| CVE-2024-9348 | HIGH | 8.9 | 0.5% | Oct 16, 2024 | Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view. |
| CVE-2024-45844 | HIGH | 8.6 | 10.6% | Oct 16, 2024 | BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdow... |
| CVE-2024-49253 | HIGH | 8.6 | 0.6% | Oct 16, 2024 | Relative Path Traversal vulnerability in JamesPark.ninja Analyse Uploads analyse-uploads allows Relative Path Traversal.... |
| CVE-2024-49251 | HIGH | 7.5 | 0.6% | Oct 16, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-49245 | HIGH | 7.5 | 0.5% | Oct 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in nahimsalami Ahime Image ... |
| CVE-2024-49226 | HIGH | 8.8 | 0.5% | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in taketin TAKETIN To WP Membership taketin-to-wp-membership allows Obje... |
| CVE-2024-48029 | HIGH | 7.5 | 0.5% | Oct 16, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-47645 | HIGH | 7.5 | 0.5% | Oct 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Danish Ali Malik Top Bar... |
| CVE-2024-47637 | HIGH | 8.8 | 0.6% | Oct 16, 2024 | Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.Th... |
| CVE-2024-47351 | HIGH | 7.5 | 0.5% | Oct 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxS... |
| CVE-2024-22032 | HIGH | 7.1 | 0.4% | Oct 16, 2024 | A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secrets encryption confi... |
| CVE-2024-22030 | HIGH | 8 | 0.4% | Oct 16, 2024 | A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-m... |
| CVE-2024-22029 | HIGH | 7.8 | 0.2% | Oct 16, 2024 | Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalat... |
| CVE-2024-49271 | HIGH | 7.2 | 1.1% | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Ad... |
| CVE-2024-10024 | HIGH | 8.8 | 0.6% | Oct 16, 2024 | A vulnerability, which was classified as critical, has been found in code-projects Pharmacy Management System 1.0. This ... |
| CVE-2024-10023 | HIGH | 8.8 | 0.5% | Oct 16, 2024 | A vulnerability classified as critical was found in code-projects Pharmacy Management System 1.0. This vulnerability aff... |
| CVE-2024-8040 | HIGH | 7.7 | 0.3% | Oct 16, 2024 | An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R... |
| CVE-2024-9858 | HIGH | 7.8 | 0.1% | Oct 16, 2024 | There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windo... |
| CVE-2024-45711 | HIGH | 8.8 | 6.3% | Oct 16, 2024 | SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible dependi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now