2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7023 | HIGH | 8.8 | 0.4% | Sep 23, 2024 | Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform priv... |
| CVE-2024-7018 | HIGH | 7.8 | 0.2% | Sep 23, 2024 | Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit hea... |
| CVE-2024-42861 | HIGH | 7.5 | 1.5% | Sep 23, 2024 | An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted... |
| CVE-2024-46639 | HIGH | 7.6 | 0.5% | Sep 23, 2024 | A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML... |
| CVE-2024-37779 | HIGH | 8.8 | 1.1% | Sep 23, 2024 | WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via t... |
| CVE-2024-39842 | HIGH | 7.2 | 1.7% | Sep 23, 2024 | A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL comm... |
| CVE-2024-0005 | HIGH | 8.8 | 0.6% | Sep 23, 2024 | A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotel... |
| CVE-2024-0004 | HIGH | 7.2 | 0.6% | Sep 23, 2024 | A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to... |
| CVE-2024-0003 | HIGH | 7.2 | 0.5% | Sep 23, 2024 | A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an ... |
| CVE-2024-40442 | HIGH | 7.2 | 1.0% | Sep 23, 2024 | An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pi... |
| CVE-2024-47066 | HIGH | 8.8 | 10.8% | Sep 23, 2024 | Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forger... |
| CVE-2024-46985 | HIGH | 7.5 | 0.7% | Sep 23, 2024 | DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity in... |
| CVE-2024-41228 | HIGH | 7.6 | 0.3% | Sep 23, 2024 | A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to es... |
| CVE-2024-23934 | HIGH | 8.8 | 1.0% | Sep 23, 2024 | Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2024-7835 | HIGH | 8.8 | 0.4% | Sep 23, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Exnet Infor... |
| CVE-2024-45348 | HIGH | 8.8 | 0.8% | Sep 23, 2024 | Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack ... |
| CVE-2024-8606 | HIGH | 8.8 | 0.4% | Sep 23, 2024 | Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass... |
| CVE-2024-9093 | HIGH | 7.2 | 0.5% | Sep 23, 2024 | A vulnerability classified as critical has been found in SourceCodester Profile Registration without Reload Refresh 1.0.... |
| CVE-2024-43989 | HIGH | 7.5 | 10.5% | Sep 23, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Firsh Justified Image Grid justified-image-grid.This issue affects J... |
| CVE-2024-9081 | HIGH | 7.5 | 0.4% | Sep 22, 2024 | A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this ... |
| CVE-2024-9076 | HIGH | 8.8 | 19.8% | Sep 22, 2024 | A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown proce... |
| CVE-2024-47221 | HIGH | 7.5 | 0.3% | Sep 22, 2024 | CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password. |
| CVE-2024-47210 | HIGH | 8.8 | 0.6% | Sep 21, 2024 | Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be... |
| CVE-2024-42323 | HIGH | 8.8 | 3.9% | Sep 21, 2024 | SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating). This vulnerability can only be ... |
| CVE-2024-6785 | HIGH | 7.1 | 0.1% | Sep 21, 2024 | The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the conf... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now