2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9054 | HIGH | 8.8 | 14.6% | Oct 4, 2024 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Inform... |
| CVE-2024-43684 | HIGH | 8.8 | 0.2% | Oct 4, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-... |
| CVE-2024-46078 | HIGH | 7.5 | 0.3% | Oct 4, 2024 | itsourcecode Sports Management System Project 1.0 is vulnerable to SQL Injection in the function delete_category of the ... |
| CVE-2024-41512 | HIGH | 8.8 | 0.7% | Oct 4, 2024 | A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attacker... |
| CVE-2024-38040 | HIGH | 7.5 | 0.5% | Oct 4, 2024 | There is a local file inclusion vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthen... |
| CVE-2024-46486 | HIGH | 8 | 0.8% | Oct 4, 2024 | TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv fu... |
| CVE-2024-47769 | HIGH | 7.5 | 0.8% | Oct 4, 2024 | IDURAR is open source ERP CRM accounting invoicing software. The vulnerability exists in the corePublicRouter.js file. U... |
| CVE-2024-47768 | HIGH | 8.1 | 0.5% | Oct 4, 2024 | Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to ... |
| CVE-2024-47183 | HIGH | 8.1 | 0.4% | Oct 4, 2024 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Ser... |
| CVE-2024-9515 | HIGH | 8.8 | 1.3% | Oct 4, 2024 | A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been classified as critical. This affects the function... |
| CVE-2024-9514 | HIGH | 8.8 | 1.4% | Oct 4, 2024 | A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been declared as critical. This vulnerability affects ... |
| CVE-2024-47790 | HIGH | 8.7 | 0.5% | Oct 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of insecure Real-... |
| CVE-2024-47789 | HIGH | 8.7 | 0.3% | Oct 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of weak authentic... |
| CVE-2024-47655 | HIGH | 8.8 | 0.7% | Oct 4, 2024 | This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than t... |
| CVE-2024-47654 | HIGH | 7.5 | 0.5% | Oct 4, 2024 | This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP request... |
| CVE-2024-47652 | HIGH | 8.1 | 0.4% | Oct 4, 2024 | This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the... |
| CVE-2024-6400 | HIGH | 7.5 | 0.6% | Oct 4, 2024 | Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finr... |
| CVE-2024-47850 | HIGH | 7.5 | 0.9% | Oct 4, 2024 | CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a sing... |
| CVE-2024-42417 | HIGH | 8.8 | 6.6% | Oct 3, 2024 | Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker... |
| CVE-2024-46658 | HIGH | 8 | 23.1% | Oct 3, 2024 | Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability. |
| CVE-2024-41596 | HIGH | 8 | 0.3% | Oct 3, 2024 | Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because o... |
| CVE-2024-41595 | HIGH | 8 | 0.3% | Oct 3, 2024 | DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cg... |
| CVE-2024-41594 | HIGH | 7.5 | 0.3% | Oct 3, 2024 | An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the http... |
| CVE-2024-41592 | HIGH | 8 | 1.4% | Oct 3, 2024 | DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because Ge... |
| CVE-2024-41590 | HIGH | 8 | 0.3% | Oct 3, 2024 | Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now