2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45710 | HIGH | 7.8 | 0.3% | Oct 16, 2024 | SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This... |
| CVE-2024-45693 | HIGH | 8.8 | 0.5% | Oct 16, 2024 | Users logged into the Apache CloudStack's web interface can be tricked to submit malicious CSRF requests due to missing ... |
| CVE-2024-45462 | HIGH | 7.1 | 0.4% | Oct 16, 2024 | The logout operation in the CloudStack web interface does not expire the user session completely which is valid until ex... |
| CVE-2024-45219 | HIGH | 8.5 | 1.2% | Oct 16, 2024 | Account users in Apache CloudStack by default are allowed to upload and register templates for deploying instances and v... |
| CVE-2024-45217 | HIGH | 8.1 | 0.7% | Oct 16, 2024 | Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore... |
| CVE-2024-8746 | HIGH | 8.8 | 0.6% | Oct 16, 2024 | The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing fi... |
| CVE-2024-8507 | HIGH | 8.8 | 0.2% | Oct 16, 2024 | The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2024-49340 | HIGH | 8.8 | 0.2% | Oct 16, 2024 | IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malic... |
| CVE-2024-38190 | HIGH | 8.6 | 1.1% | Oct 15, 2024 | Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a netwo... |
| CVE-2024-38139 | HIGH | 8.8 | 0.8% | Oct 15, 2024 | Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. |
| CVE-2024-45085 | HIGH | 7.5 | 0.6% | Oct 15, 2024 | IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an un... |
| CVE-2024-9965 | HIGH | 8.8 | 0.4% | Oct 15, 2024 | Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker wh... |
| CVE-2024-9961 | HIGH | 8.8 | 0.4% | Oct 15, 2024 | Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced ... |
| CVE-2024-9960 | HIGH | 7.5 | 0.4% | Oct 15, 2024 | Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2024-9959 | HIGH | 8.8 | 0.3% | Oct 15, 2024 | Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the ren... |
| CVE-2024-9957 | HIGH | 8.8 | 0.4% | Oct 15, 2024 | Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to en... |
| CVE-2024-9956 | HIGH | 7.8 | 0.4% | Oct 15, 2024 | Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local att... |
| CVE-2024-9955 | HIGH | 8.8 | 0.8% | Oct 15, 2024 | Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exp... |
| CVE-2024-9954 | HIGH | 8.8 | 6.3% | Oct 15, 2024 | Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2024-9594 | HIGH | 8.1 | 1.6% | Oct 15, 2024 | A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enable... |
| CVE-2024-48783 | HIGH | 7.5 | 0.4% | Oct 15, 2024 | An issue in Ruijie NBR3000D-E Gateway allows a remote attacker to obtain sensitive information via the /tool/shell/postg... |
| CVE-2024-44775 | HIGH | 7.5 | 0.5% | Oct 15, 2024 | kmqtt v0.2.7 is vulnerable to Denial of Service (DoS) due to a Null Pointer Exception. A remote attacker can cause the b... |
| CVE-2024-41311 | HIGH | 8.1 | 0.8% | Oct 15, 2024 | In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with fo... |
| CVE-2024-21285 | HIGH | 7.1 | 0.3% | Oct 15, 2024 | Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: R... |
| CVE-2024-21284 | HIGH | 7.1 | 0.3% | Oct 15, 2024 | Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: R... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now