2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32842 | HIGH | 7.2 | 2.1% | Sep 12, 2024 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a... |
| CVE-2024-32840 | HIGH | 7.2 | 25.4% | Sep 12, 2024 | An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated a... |
| CVE-2024-28981 | HIGH | 8.5 | 0.3% | Sep 12, 2024 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses da... |
| CVE-2024-7890 | HIGH | 7.3 | 0.2% | Sep 11, 2024 | Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows |
| CVE-2024-7889 | HIGH | 7.3 | 0.2% | Sep 11, 2024 | Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows |
| CVE-2024-42760 | HIGH | 7.5 | 0.6% | Sep 11, 2024 | SQL Injection vulnerability in Ellevo v.6.2.0.38160 allows a remote attacker to obtain sensitive information via the /ap... |
| CVE-2024-8691 | HIGH | 7.1 | 0.3% | Sep 11, 2024 | A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated Glob... |
| CVE-2024-8687 | HIGH | 7.1 | 0.4% | Sep 11, 2024 | An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user... |
| CVE-2024-8686 | HIGH | 7.2 | 1.4% | Sep 11, 2024 | A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass... |
| CVE-2024-44577 | HIGH | 8.8 | 1.1% | Sep 11, 2024 | RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function. |
| CVE-2024-44574 | HIGH | 8.8 | 1.1% | Sep 11, 2024 | RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function. |
| CVE-2024-44572 | HIGH | 8.8 | 1.1% | Sep 11, 2024 | RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function. |
| CVE-2024-44571 | HIGH | 8.8 | 0.4% | Sep 11, 2024 | RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php. |
| CVE-2024-44570 | HIGH | 8.8 | 0.5% | Sep 11, 2024 | RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpi... |
| CVE-2024-20483 | HIGH | 7.2 | 1.1% | Sep 11, 2024 | Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is s... |
| CVE-2024-20406 | HIGH | 7.4 | 0.2% | Sep 11, 2024 | A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (IS-IS) protocol of Ci... |
| CVE-2024-20398 | HIGH | 7.8 | 0.2% | Sep 11, 2024 | A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write fi... |
| CVE-2024-20381 | HIGH | 8.8 | 0.6% | Sep 11, 2024 | A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is use... |
| CVE-2024-20317 | HIGH | 7.4 | 0.2% | Sep 11, 2024 | A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergen... |
| CVE-2024-20304 | HIGH | 7.5 | 0.6% | Sep 11, 2024 | A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthen... |
| CVE-2024-5760 | HIGH | 7.8 | 0.1% | Sep 11, 2024 | The Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creatio... |
| CVE-2024-45026 | HIGH | 7.8 | 0.2% | Sep 11, 2024 | In the Linux kernel, the following vulnerability has been resolved: s390/dasd: fix error recovery leading to data corru... |
| CVE-2024-45023 | HIGH | 7.1 | 0.2% | Sep 11, 2024 | In the Linux kernel, the following vulnerability has been resolved: md/raid1: Fix data corruption for degraded array wi... |
| CVE-2024-39378 | HIGH | 7.8 | 0.2% | Sep 11, 2024 | Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds write vulnerability that could result in a... |
| CVE-2024-8306 | HIGH | 7.8 | 0.2% | Sep 11, 2024 | CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentialit... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now