2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8711 | HIGH | 7.5 | 0.8% | Sep 12, 2024 | A vulnerability, which was classified as problematic, has been found in SourceCodester Food Ordering Management System 1... |
| CVE-2024-8710 | HIGH | 8.8 | 0.6% | Sep 12, 2024 | A vulnerability classified as critical was found in code-projects Inventory Management 1.0. Affected by this vulnerabili... |
| CVE-2024-8709 | HIGH | 8.8 | 0.6% | Sep 12, 2024 | A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affecte... |
| CVE-2024-37397 | HIGH | 8.2 | 59.3% | Sep 12, 2024 | An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 Se... |
| CVE-2024-34785 | HIGH | 7.2 | 25.4% | Sep 12, 2024 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a... |
| CVE-2024-34783 | HIGH | 7.2 | 43.4% | Sep 12, 2024 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a... |
| CVE-2024-34779 | HIGH | 7.2 | 24.0% | Sep 12, 2024 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a... |
| CVE-2024-32848 | HIGH | 7.2 | 43.4% | Sep 12, 2024 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a... |
| CVE-2024-32846 | HIGH | 7.2 | 2.1% | Sep 12, 2024 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a... |
| CVE-2024-32845 | HIGH | 7.2 | 24.0% | Sep 12, 2024 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a... |
| CVE-2024-32843 | HIGH | 7.2 | 2.1% | Sep 12, 2024 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a... |
| CVE-2024-32842 | HIGH | 7.2 | 2.1% | Sep 12, 2024 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a... |
| CVE-2024-32840 | HIGH | 7.2 | 25.4% | Sep 12, 2024 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a... |
| CVE-2024-28981 | HIGH | 8.5 | 0.3% | Sep 12, 2024 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses da... |
| CVE-2024-7890 | HIGH | 7.3 | 0.2% | Sep 11, 2024 | Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows |
| CVE-2024-7889 | HIGH | 7.3 | 0.2% | Sep 11, 2024 | Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows |
| CVE-2024-42760 | HIGH | 7.5 | 0.6% | Sep 11, 2024 | SQL Injection vulnerability in Ellevo v.6.2.0.38160 allows a remote attacker to obtain sensitive information via the /ap... |
| CVE-2024-8691 | HIGH | 7.1 | 0.3% | Sep 11, 2024 | A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated Glob... |
| CVE-2024-8687 | HIGH | 7.1 | 0.4% | Sep 11, 2024 | An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user... |
| CVE-2024-8686 | HIGH | 7.2 | 1.4% | Sep 11, 2024 | A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass... |
| CVE-2024-44577 | HIGH | 8.8 | 1.1% | Sep 11, 2024 | RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function. |
| CVE-2024-44574 | HIGH | 8.8 | 1.1% | Sep 11, 2024 | RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function. |
| CVE-2024-44572 | HIGH | 8.8 | 1.1% | Sep 11, 2024 | RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function. |
| CVE-2024-44571 | HIGH | 8.8 | 0.4% | Sep 11, 2024 | RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php. |
| CVE-2024-44570 | HIGH | 8.8 | 0.5% | Sep 11, 2024 | RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now