2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23938 | HIGH | 8.8 | 0.9% | Sep 28, 2024 | Silicon Labs Gecko OS Debug Interface Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerabilit... |
| CVE-2024-23586 | HIGH | 7.5 | 0.3% | Sep 27, 2024 | HCL Nomad is susceptible to an insufficient session expiration vulnerability. Under certain circumstances, an unauthen... |
| CVE-2024-9293 | HIGH | 8.8 | 0.5% | Sep 27, 2024 | A vulnerability classified as critical was found in skyselang yylAdmin up to 3.0. Affected by this vulnerability is the ... |
| CVE-2024-33369 | HIGH | 8.8 | 1.1% | Sep 27, 2024 | Directory Traversal vulnerability in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary ... |
| CVE-2024-33368 | HIGH | 8.8 | 0.7% | Sep 27, 2024 | An issue in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the build method... |
| CVE-2024-9301 | HIGH | 7.5 | 0.7% | Sep 27, 2024 | A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a |
| CVE-2024-46097 | HIGH | 8.1 | 0.4% | Sep 27, 2024 | TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is create... |
| CVE-2024-39364 | HIGH | 7 | 0.2% | Sep 27, 2024 | Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow f... |
| CVE-2024-39275 | HIGH | 8.8 | 0.4% | Sep 27, 2024 | Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging req... |
| CVE-2024-28948 | HIGH | 8.8 | 0.2% | Sep 27, 2024 | Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumve... |
| CVE-2024-9284 | HIGH | 7.1 | 0.9% | Sep 27, 2024 | A vulnerability was found in TP-LINK TL-WR841ND up to 20240920. It has been rated as critical. Affected by this issue is... |
| CVE-2024-46366 | HIGH | 8.8 | 0.5% | Sep 27, 2024 | A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbi... |
| CVE-2024-6983 | HIGH | 8.8 | 1.3% | Sep 27, 2024 | mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backe... |
| CVE-2024-46472 | HIGH | 8.6 | 0.4% | Sep 27, 2024 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page. |
| CVE-2024-46471 | HIGH | 7.5 | 0.5% | Sep 27, 2024 | The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and conten... |
| CVE-2024-46331 | HIGH | 7.2 | 0.6% | Sep 27, 2024 | ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. T... |
| CVE-2024-44912 | HIGH | 7.5 | 0.5% | Sep 27, 2024 | NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TM subsystem (crypto_tm.c). |
| CVE-2024-44911 | HIGH | 7.5 | 0.5% | Sep 27, 2024 | NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TC subsystem (crypto_tc.c). |
| CVE-2024-44910 | HIGH | 7.5 | 0.5% | Sep 27, 2024 | NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (crypto_aos.c). |
| CVE-2024-40510 | HIGH | 8.2 | 0.7% | Sep 27, 2024 | Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t... |
| CVE-2024-40509 | HIGH | 7.3 | 0.8% | Sep 27, 2024 | Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t... |
| CVE-2024-7149 | HIGH | 8.8 | 1.0% | Sep 27, 2024 | The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File In... |
| CVE-2024-47182 | HIGH | 7.5 | 0.2% | Sep 27, 2024 | Dozzle is a realtime log viewer for docker containers. Before version 8.5.3, the app uses sha-256 as the hash for passwo... |
| CVE-2024-45773 | HIGH | 7.5 | 0.5% | Sep 27, 2024 | A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash or potentially resu... |
| CVE-2024-40512 | HIGH | 7.3 | 0.7% | Sep 27, 2024 | Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now