2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21215 | HIGH | 7.5 | 0.6% | Oct 15, 2024 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t... |
| CVE-2024-21214 | HIGH | 8.1 | 0.5% | Oct 15, 2024 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versi... |
| CVE-2024-21195 | HIGH | 7.6 | 0.4% | Oct 15, 2024 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates). Supported versions ... |
| CVE-2024-21191 | HIGH | 7.6 | 0.4% | Oct 15, 2024 | Vulnerability in the Oracle Enterprise Manager Fusion Middleware Control product of Oracle Fusion Middleware (component:... |
| CVE-2024-21190 | HIGH | 7.5 | 0.5% | Oct 15, 2024 | Vulnerability in the Oracle Global Lifecycle Management FMW Installer product of Oracle Fusion Middleware (component: Cl... |
| CVE-2024-41344 | HIGH | 7.5 | 0.2% | Oct 15, 2024 | A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator passw... |
| CVE-2024-35584 | HIGH | 8.8 | 5.9% | Oct 15, 2024 | SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingL... |
| CVE-2024-5749 | HIGH | 7.5 | 1.2% | Oct 15, 2024 | Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials. |
| CVE-2024-48915 | HIGH | 8.7 | 0.4% | Oct 15, 2024 | Agent Dart is an agent library built for Internet Computer for Dart and Flutter apps. Prior to version 1.0.0-dev.29, cer... |
| CVE-2024-47876 | HIGH | 8.8 | 0.6% | Oct 15, 2024 | Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users crea... |
| CVE-2024-47874 | HIGH | 8.7 | 0.7% | Oct 15, 2024 | Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit. Prior to version 0.40.0, Starlette treat... |
| CVE-2024-47824 | HIGH | 8.7 | 0.7% | Oct 15, 2024 | matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starti... |
| CVE-2024-47779 | HIGH | 7 | 0.4% | Oct 15, 2024 | Element is a Matrix web client built using the Matrix React SDK. Element Web versions 1.11.70 through 1.11.80 contain a ... |
| CVE-2024-47771 | HIGH | 7 | 0.6% | Oct 15, 2024 | Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vul... |
| CVE-2024-47080 | HIGH | 8.7 | 0.7% | Oct 15, 2024 | matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 t... |
| CVE-2024-48282 | HIGH | 7.6 | 0.4% | Oct 15, 2024 | A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Manag... |
| CVE-2024-48280 | HIGH | 7.6 | 0.4% | Oct 15, 2024 | A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Managemen... |
| CVE-2024-48279 | HIGH | 7.6 | 0.6% | Oct 15, 2024 | A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Manageme... |
| CVE-2024-9975 | HIGH | 8.8 | 0.6% | Oct 15, 2024 | A vulnerability was found in SourceCodester Drag and Drop Image Upload 1.0. It has been rated as critical. Affected by t... |
| CVE-2024-49387 | HIGH | 7.5 | 0.2% | Oct 15, 2024 | Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis ... |
| CVE-2024-45276 | HIGH | 7.5 | 0.6% | Oct 15, 2024 | An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication. |
| CVE-2024-45273 | HIGH | 7.8 | 0.1% | Oct 15, 2024 | An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak ... |
| CVE-2024-45272 | HIGH | 7.5 | 0.6% | Oct 15, 2024 | An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with... |
| CVE-2024-45271 | HIGH | 7.8 | 0.3% | Oct 15, 2024 | An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation. |
| CVE-2024-9983 | HIGH | 7.5 | 0.7% | Oct 15, 2024 | Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now