2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37979 | HIGH | 7.8 | 0.6% | Oct 8, 2024 | Windows Kernel Elevation of Privilege Vulnerability |
| CVE-2024-30092 | HIGH | 7.5 | 0.7% | Oct 8, 2024 | Windows Hyper-V Remote Code Execution Vulnerability |
| CVE-2024-25885 | HIGH | 7.5 | 0.6% | Oct 8, 2024 | An issue in the getcolor function in utils.py of xhtml2pdf v0.2.13 allows attackers to cause a Regular expression Denial... |
| CVE-2024-20659 | HIGH | 7.1 | 0.9% | Oct 8, 2024 | Windows Hyper-V Security Feature Bypass Vulnerability |
| CVE-2024-9381 | HIGH | 7.2 | 15.7% | Oct 8, 2024 | Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass... |
| CVE-2024-9380 | HIGH | 7.2 | 63.0% | Oct 8, 2024 | An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authen... |
| CVE-2024-9379 | HIGH | 7.2 | 43.8% | Oct 8, 2024 | SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with ad... |
| CVE-2024-9167 | HIGH | 7.8 | 0.2% | Oct 8, 2024 | Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local a... |
| CVE-2024-9124 | HIGH | 7.5 | 0.5% | Oct 8, 2024 | A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 600T. If the device is overloaded with re... |
| CVE-2024-8626 | HIGH | 7.5 | 0.5% | Oct 8, 2024 | Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious... |
| CVE-2024-7612 | HIGH | 7.8 | 0.2% | Oct 8, 2024 | Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application... |
| CVE-2024-47011 | HIGH | 7.5 | 57.0% | Oct 8, 2024 | Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive infor... |
| CVE-2024-47008 | HIGH | 7.5 | 46.6% | Oct 8, 2024 | Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak se... |
| CVE-2024-47007 | HIGH | 7.5 | 1.2% | Oct 8, 2024 | A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenti... |
| CVE-2024-8215 | HIGH | 8.4 | 0.4% | Oct 8, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Plat... |
| CVE-2024-47949 | HIGH | 7.5 | 22.9% | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location |
| CVE-2024-47948 | HIGH | 7.5 | 0.5% | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups |
| CVE-2024-45230 | HIGH | 7.5 | 25.3% | Oct 8, 2024 | An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrun... |
| CVE-2024-45880 | HIGH | 8 | 0.9% | Oct 8, 2024 | A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the S... |
| CVE-2024-45330 | HIGH | 7.2 | 0.6% | Oct 8, 2024 | A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5... |
| CVE-2024-9005 | HIGH | 7.3 | 0.3% | Oct 8, 2024 | CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the ser... |
| CVE-2024-8422 | HIGH | 7.8 | 0.2% | Oct 8, 2024 | CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of co... |
| CVE-2024-3506 | HIGH | 7.3 | 0.2% | Oct 8, 2024 | A possible buffer overflow in selected cameras' drivers from XProtect Device Pack can allow an attacker with access to i... |
| CVE-2024-47562 | HIGH | 8.8 | 0.3% | Oct 8, 2024 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not... |
| CVE-2024-47196 | HIGH | 7.3 | 0.2% | Oct 8, 2024 | A vulnerability has been identified in ModelSim (All versions < V2025.2), Questa (All versions < V2025.2). vsimk.exe in ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now