2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7994 | HIGH | 7.8 | 0.2% | Oct 16, 2024 | A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Stack-Based Buffer Overflow. A malicious... |
| CVE-2024-7993 | HIGH | 7.8 | 0.2% | Oct 16, 2024 | A maliciously crafted PDF file, when parsed through Autodesk Revit, may force an Out-of-Bounds Write vulnerability. A ma... |
| CVE-2024-48918 | HIGH | 8.1 | 0.4% | Oct 16, 2024 | RDS Light is a simplified version of the Reflective Dialogue System (RDS), a self-reflecting AI framework. Versions prio... |
| CVE-2024-46213 | HIGH | 7.2 | 1.0% | Oct 16, 2024 | REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability. |
| CVE-2024-47522 | HIGH | 7.5 | 0.6% | Oct 16, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-47188 | HIGH | 7.5 | 0.3% | Oct 16, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-47187 | HIGH | 7.5 | 0.3% | Oct 16, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-45797 | HIGH | 7.5 | 0.7% | Oct 16, 2024 | LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Prior to version 0.5.49, unboun... |
| CVE-2024-45795 | HIGH | 7.5 | 0.5% | Oct 16, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-4690 | HIGH | 8 | 0.4% | Oct 16, 2024 | Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD ... |
| CVE-2024-4189 | HIGH | 8 | 0.4% | Oct 16, 2024 | Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD ... |
| CVE-2024-4184 | HIGH | 8 | 0.4% | Oct 16, 2024 | Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD ... |
| CVE-2024-38814 | HIGH | 8.8 | 14.6% | Oct 16, 2024 | An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated ... |
| CVE-2024-20463 | HIGH | 7.1 | 0.3% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al... |
| CVE-2024-20459 | HIGH | 7.2 | 0.7% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Multiplatform Series Analog Telephone Adapter fir... |
| CVE-2024-20458 | HIGH | 8.2 | 0.7% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al... |
| CVE-2024-20420 | HIGH | 8.8 | 0.4% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al... |
| CVE-2024-9348 | HIGH | 8.9 | 0.5% | Oct 16, 2024 | Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view. |
| CVE-2024-45844 | HIGH | 8.6 | 10.6% | Oct 16, 2024 | BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdow... |
| CVE-2024-49253 | HIGH | 8.6 | 0.6% | Oct 16, 2024 | Relative Path Traversal vulnerability in JamesPark.ninja Analyse Uploads analyse-uploads allows Relative Path Traversal.... |
| CVE-2024-49251 | HIGH | 7.5 | 0.6% | Oct 16, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-49245 | HIGH | 7.5 | 0.5% | Oct 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in nahimsalami Ahime Image ... |
| CVE-2024-49226 | HIGH | 8.8 | 0.5% | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in taketin TAKETIN To WP Membership taketin-to-wp-membership allows Obje... |
| CVE-2024-48029 | HIGH | 7.5 | 0.5% | Oct 16, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-47645 | HIGH | 7.5 | 0.5% | Oct 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Danish Ali Malik Top Bar... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now