2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-46985 | HIGH | 7.5 | 0.7% | Sep 23, 2024 | DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity in... |
| CVE-2024-41228 | HIGH | 7.6 | 0.3% | Sep 23, 2024 | A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to es... |
| CVE-2024-23934 | HIGH | 8.8 | 1.0% | Sep 23, 2024 | Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2024-7835 | HIGH | 8.8 | 0.4% | Sep 23, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Exnet Infor... |
| CVE-2024-45348 | HIGH | 8.8 | 0.8% | Sep 23, 2024 | Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack ... |
| CVE-2024-8606 | HIGH | 8.8 | 0.4% | Sep 23, 2024 | Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass... |
| CVE-2024-9093 | HIGH | 7.2 | 0.5% | Sep 23, 2024 | A vulnerability classified as critical has been found in SourceCodester Profile Registration without Reload Refresh 1.0.... |
| CVE-2024-43989 | HIGH | 7.5 | 10.5% | Sep 23, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Firsh Justified Image Grid justified-image-grid.This issue affects J... |
| CVE-2024-9081 | HIGH | 7.5 | 0.4% | Sep 22, 2024 | A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this ... |
| CVE-2024-9076 | HIGH | 8.8 | 19.8% | Sep 22, 2024 | A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown proce... |
| CVE-2024-47221 | HIGH | 7.5 | 0.3% | Sep 22, 2024 | CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password. |
| CVE-2024-47210 | HIGH | 8.8 | 0.6% | Sep 21, 2024 | Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be... |
| CVE-2024-42323 | HIGH | 8.8 | 3.9% | Sep 21, 2024 | SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating). This vulnerability can only be ... |
| CVE-2024-6785 | HIGH | 7.1 | 0.1% | Sep 21, 2024 | The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the conf... |
| CVE-2024-46649 | HIGH | 7.5 | 0.9% | Sep 20, 2024 | eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder. |
| CVE-2024-46648 | HIGH | 7.5 | 0.9% | Sep 20, 2024 | eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder. |
| CVE-2024-46645 | HIGH | 7.5 | 0.9% | Sep 20, 2024 | eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files. |
| CVE-2024-47062 | HIGH | 8.8 | 4.5% | Sep 20, 2024 | Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in t... |
| CVE-2024-47061 | HIGH | 8.3 | 0.5% | Sep 20, 2024 | Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text ... |
| CVE-2024-9041 | HIGH | 8.8 | 0.6% | Sep 20, 2024 | A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical. Thi... |
| CVE-2024-9037 | HIGH | 7.3 | 0.6% | Sep 20, 2024 | A vulnerability classified as critical has been found in Codezips Internal Marks Calculation 1.0. Affected is an unknown... |
| CVE-2024-9035 | HIGH | 7.3 | 0.6% | Sep 20, 2024 | A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. This af... |
| CVE-2024-9034 | HIGH | 7.3 | 0.5% | Sep 20, 2024 | A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by ... |
| CVE-2024-9032 | HIGH | 8.8 | 0.7% | Sep 20, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0. Affec... |
| CVE-2024-41721 | HIGH | 8.1 | 0.8% | Sep 20, 2024 | An insufficient boundary validation in the USB code could lead to an out-of-bounds read on the heap, which could potenti... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now