2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47637 | HIGH | 8.8 | 0.6% | Oct 16, 2024 | Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.Th... |
| CVE-2024-47351 | HIGH | 7.5 | 0.5% | Oct 16, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxS... |
| CVE-2024-22032 | HIGH | 7.1 | 0.4% | Oct 16, 2024 | A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secrets encryption confi... |
| CVE-2024-22030 | HIGH | 8 | 0.4% | Oct 16, 2024 | A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-m... |
| CVE-2024-22029 | HIGH | 7.8 | 0.2% | Oct 16, 2024 | Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalat... |
| CVE-2024-49271 | HIGH | 7.2 | 1.1% | Oct 16, 2024 | Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Ad... |
| CVE-2024-10024 | HIGH | 8.8 | 0.6% | Oct 16, 2024 | A vulnerability, which was classified as critical, has been found in code-projects Pharmacy Management System 1.0. This ... |
| CVE-2024-10023 | HIGH | 8.8 | 0.5% | Oct 16, 2024 | A vulnerability classified as critical was found in code-projects Pharmacy Management System 1.0. This vulnerability aff... |
| CVE-2024-8040 | HIGH | 7.7 | 0.3% | Oct 16, 2024 | An authorization bypass through user-controlled key vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R... |
| CVE-2024-9858 | HIGH | 7.8 | 0.1% | Oct 16, 2024 | There exists an insecure default user permission in Google Cloud Migrate to containers from version 1.1.0 to 1.2.2 Windo... |
| CVE-2024-45711 | HIGH | 8.8 | 6.3% | Oct 16, 2024 | SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible dependi... |
| CVE-2024-45710 | HIGH | 7.8 | 0.3% | Oct 16, 2024 | SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This... |
| CVE-2024-45693 | HIGH | 8.8 | 0.5% | Oct 16, 2024 | Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing ... |
| CVE-2024-45462 | HIGH | 7.1 | 0.4% | Oct 16, 2024 | The logout operation in the CloudStack web interface does not expire the user session completely which is valid until ex... |
| CVE-2024-45219 | HIGH | 8.5 | 1.2% | Oct 16, 2024 | Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and v... |
| CVE-2024-45217 | HIGH | 8.1 | 0.7% | Oct 16, 2024 | Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore... |
| CVE-2024-8746 | HIGH | 8.8 | 0.6% | Oct 16, 2024 | The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing fi... |
| CVE-2024-8507 | HIGH | 8.8 | 0.2% | Oct 16, 2024 | The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2024-49340 | HIGH | 8.8 | 0.2% | Oct 16, 2024 | IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malic... |
| CVE-2024-38190 | HIGH | 8.6 | 1.1% | Oct 15, 2024 | Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a netwo... |
| CVE-2024-38139 | HIGH | 8.8 | 0.8% | Oct 15, 2024 | Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. |
| CVE-2024-45085 | HIGH | 7.5 | 0.6% | Oct 15, 2024 | IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an un... |
| CVE-2024-9965 | HIGH | 8.8 | 0.4% | Oct 15, 2024 | Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker wh... |
| CVE-2024-9961 | HIGH | 8.8 | 0.4% | Oct 15, 2024 | Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced ... |
| CVE-2024-9960 | HIGH | 7.5 | 0.4% | Oct 15, 2024 | Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap cor... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now