2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47000 | HIGH | 7.5 | 0.4% | Sep 20, 2024 | Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work corre... |
| CVE-2024-45810 | HIGH | 7.5 | 0.6% | Sep 20, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy will crash when the http async client is handl... |
| CVE-2024-45809 | HIGH | 7.5 | 0.4% | Sep 20, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. Jwt filter will lead to an Envoy crash when clear ro... |
| CVE-2024-45807 | HIGH | 7.5 | 0.5% | Sep 20, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2... |
| CVE-2024-9006 | HIGH | 8.8 | 0.7% | Sep 19, 2024 | A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some ... |
| CVE-2024-45410 | HIGH | 7.5 | 1.5% | Sep 19, 2024 | Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers s... |
| CVE-2024-43496 | HIGH | 8.8 | 1.0% | Sep 19, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2024-43489 | HIGH | 8.8 | 0.7% | Sep 19, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2024-9001 | HIGH | 8.8 | 3.9% | Sep 19, 2024 | A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the... |
| CVE-2024-38016 | HIGH | 7.8 | 0.6% | Sep 19, 2024 | Microsoft Office Visio Remote Code Execution Vulnerability |
| CVE-2024-8698 | HIGH | 7.7 | 2.0% | Sep 19, 2024 | A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly... |
| CVE-2024-8375 | HIGH | 7.8 | 0.1% | Sep 19, 2024 | There exists a use after free vulnerability in Reverb. Reverb supports the VARIANT datatype, which is supposed to repres... |
| CVE-2024-7737 | HIGH | 8.7 | 0.4% | Sep 19, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through ... |
| CVE-2024-45862 | HIGH | 7.5 | 0.2% | Sep 19, 2024 | Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to ac... |
| CVE-2024-45861 | HIGH | 7.5 | 0.4% | Sep 19, 2024 | Kastle Systems firmware prior to May 1, 2024, contained a hard-coded credential, which if accessed may allow an attacker... |
| CVE-2024-45752 | HIGH | 7.3 | 0.3% | Sep 19, 2024 | logiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an u... |
| CVE-2024-46394 | HIGH | 8.8 | 0.3% | Sep 19, 2024 | FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add |
| CVE-2024-46382 | HIGH | 7.5 | 0.6% | Sep 19, 2024 | A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via ... |
| CVE-2024-7254 | HIGH | 7.5 | 2.8% | Sep 19, 2024 | Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGRO... |
| CVE-2024-37406 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, w... |
| CVE-2024-46373 | HIGH | 8.8 | 0.5% | Sep 18, 2024 | Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend. |
| CVE-2024-44589 | HIGH | 8.8 | 0.9% | Sep 18, 2024 | Stack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows atta... |
| CVE-2024-39339 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota c... |
| CVE-2024-8287 | HIGH | 7.5 | 0.2% | Sep 18, 2024 | Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the... |
| CVE-2024-34057 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing re... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now