2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-46649 | HIGH | 7.5 | 0.9% | Sep 20, 2024 | eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder. |
| CVE-2024-46648 | HIGH | 7.5 | 0.9% | Sep 20, 2024 | eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder. |
| CVE-2024-46645 | HIGH | 7.5 | 0.9% | Sep 20, 2024 | eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files. |
| CVE-2024-47062 | HIGH | 8.8 | 4.5% | Sep 20, 2024 | Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in t... |
| CVE-2024-47061 | HIGH | 8.3 | 0.5% | Sep 20, 2024 | Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text ... |
| CVE-2024-9041 | HIGH | 8.8 | 0.6% | Sep 20, 2024 | A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as critical. Thi... |
| CVE-2024-9037 | HIGH | 7.3 | 0.6% | Sep 20, 2024 | A vulnerability classified as critical has been found in Codezips Internal Marks Calculation 1.0. Affected is an unknown... |
| CVE-2024-9035 | HIGH | 7.3 | 0.6% | Sep 20, 2024 | A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. This af... |
| CVE-2024-9034 | HIGH | 7.3 | 0.5% | Sep 20, 2024 | A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by ... |
| CVE-2024-9032 | HIGH | 8.8 | 0.7% | Sep 20, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0. Affec... |
| CVE-2024-41721 | HIGH | 8.1 | 0.8% | Sep 20, 2024 | An insufficient boundary validation in the USB code could lead to an out-of-bounds read on the heap, which could potenti... |
| CVE-2024-47000 | HIGH | 7.5 | 0.4% | Sep 20, 2024 | Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work corre... |
| CVE-2024-45810 | HIGH | 7.5 | 0.6% | Sep 20, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy will crash when the http async client is handl... |
| CVE-2024-45809 | HIGH | 7.5 | 0.4% | Sep 20, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. Jwt filter will lead to an Envoy crash when clear ro... |
| CVE-2024-45807 | HIGH | 7.5 | 0.5% | Sep 20, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2... |
| CVE-2024-9006 | HIGH | 8.8 | 0.7% | Sep 19, 2024 | A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some ... |
| CVE-2024-45410 | HIGH | 7.5 | 1.5% | Sep 19, 2024 | Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers s... |
| CVE-2024-43496 | HIGH | 8.8 | 1.0% | Sep 19, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2024-43489 | HIGH | 8.8 | 0.7% | Sep 19, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2024-9001 | HIGH | 8.8 | 3.9% | Sep 19, 2024 | A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the... |
| CVE-2024-38016 | HIGH | 7.8 | 0.6% | Sep 19, 2024 | Microsoft Office Visio Remote Code Execution Vulnerability |
| CVE-2024-8698 | HIGH | 7.7 | 2.0% | Sep 19, 2024 | A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly... |
| CVE-2024-8375 | HIGH | 7.8 | 0.1% | Sep 19, 2024 | There exists a use after free vulnerability in Reverb. Reverb supports the VARIANT datatype, which is supposed to repres... |
| CVE-2024-7737 | HIGH | 8.7 | 0.4% | Sep 19, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through ... |
| CVE-2024-45862 | HIGH | 7.5 | 0.2% | Sep 19, 2024 | Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to ac... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now