2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48957 | HIGH | 7.8 | 0.5% | Oct 10, 2024 | execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a c... |
| CVE-2024-39525 | HIGH | 8.7 | 0.4% | Oct 9, 2024 | An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Ju... |
| CVE-2024-39516 | HIGH | 8.7 | 0.4% | Oct 9, 2024 | An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS E... |
| CVE-2024-39515 | HIGH | 8.7 | 0.4% | Oct 9, 2024 | An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Network... |
| CVE-2024-3656 | HIGH | 8.1 | 2.8% | Oct 9, 2024 | A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access adminis... |
| CVE-2024-9473 | HIGH | 7.8 | 0.3% | Oct 9, 2024 | A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticat... |
| CVE-2024-9468 | HIGH | 7.5 | 0.4% | Oct 9, 2024 | A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-... |
| CVE-2024-9463 | HIGH | 7.5 | 98.4% | Oct 9, 2024 | An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitra... |
| CVE-2024-46307 | HIGH | 7.5 | 0.5% | Oct 9, 2024 | A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products. |
| CVE-2024-43610 | HIGH | 7.5 | 1.0% | Oct 9, 2024 | Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view s... |
| CVE-2024-46316 | HIGH | 8 | 1.1% | Oct 9, 2024 | DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cg... |
| CVE-2024-46304 | HIGH | 7.5 | 0.5% | Oct 9, 2024 | A NULL pointer dereference in libcoap v4.3.5-rc2 and below allows a remote attacker to cause a denial of service via the... |
| CVE-2024-46292 | HIGH | 7.5 | 0.8% | Oct 9, 2024 | A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserte... |
| CVE-2024-8048 | HIGH | 7.8 | 0.2% | Oct 9, 2024 | In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object ... |
| CVE-2024-8015 | HIGH | 7.2 | 0.8% | Oct 9, 2024 | In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible th... |
| CVE-2024-8014 | HIGH | 8.8 | 0.6% | Oct 9, 2024 | In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through objec... |
| CVE-2024-7840 | HIGH | 7.8 | 0.7% | Oct 9, 2024 | In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through im... |
| CVE-2024-7293 | HIGH | 8.8 | 0.3% | Oct 9, 2024 | In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible... |
| CVE-2024-7292 | HIGH | 8.8 | 0.3% | Oct 9, 2024 | In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible th... |
| CVE-2024-47670 | HIGH | 7.8 | 0.2% | Oct 9, 2024 | In the Linux kernel, the following vulnerability has been resolved: ocfs2: add bounds checking to ocfs2_xattr_find_entr... |
| CVE-2024-47425 | HIGH | 7.8 | 0.3% | Oct 9, 2024 | Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerabi... |
| CVE-2024-47424 | HIGH | 7.8 | 0.3% | Oct 9, 2024 | Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability tha... |
| CVE-2024-47423 | HIGH | 7.8 | 0.3% | Oct 9, 2024 | Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Unrestricted Upload of File with Dangerous Type ... |
| CVE-2024-47422 | HIGH | 7.8 | 0.3% | Oct 9, 2024 | Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Untrusted Search Path vulnerability that could l... |
| CVE-2024-47421 | HIGH | 7.8 | 0.4% | Oct 9, 2024 | Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now