2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48793 | MEDIUM | 5.9 | 0.3% | Oct 14, 2024 | An issue in INATRONIC com.inatronic.bmw 2.7.1 allows a remote attacker to obtain sensitive information via the firmware ... |
| CVE-2024-48790 | MEDIUM | 5.3 | 0.3% | Oct 14, 2024 | An issue in ILIFE com.ilife.home.global 1.8.7 allows a remote attacker to obtain sensitive information via the firmware ... |
| CVE-2024-47826 | MEDIUM | 6.1 | 0.3% | Oct 14, 2024 | eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows a... |
| CVE-2024-47767 | MEDIUM | 4.3 | 0.4% | Oct 14, 2024 | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1... |
| CVE-2024-47766 | MEDIUM | 4.9 | 0.5% | Oct 14, 2024 | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1... |
| CVE-2024-46988 | MEDIUM | 5.7 | 0.3% | Oct 14, 2024 | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1... |
| CVE-2024-46980 | MEDIUM | 4.8 | 0.3% | Oct 14, 2024 | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1... |
| CVE-2024-46528 | MEDIUM | 4.3 | 1.6% | Oct 14, 2024 | An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSp... |
| CVE-2024-45741 | MEDIUM | 5.4 | 12.9% | Oct 14, 2024 | In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.2... |
| CVE-2024-45740 | MEDIUM | 5.4 | 0.4% | Oct 14, 2024 | In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403, a low-privileged ... |
| CVE-2024-45739 | MEDIUM | 4.9 | 0.5% | Oct 14, 2024 | In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for lo... |
| CVE-2024-45738 | MEDIUM | 4.9 | 0.5% | Oct 14, 2024 | In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters ... |
| CVE-2024-45736 | MEDIUM | 6.5 | 0.5% | Oct 14, 2024 | In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2... |
| CVE-2024-45735 | MEDIUM | 4.3 | 0.3% | Oct 14, 2024 | In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform version... |
| CVE-2024-45734 | MEDIUM | 4.3 | 0.3% | Oct 14, 2024 | In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" S... |
| CVE-2024-45732 | MEDIUM | 6.5 | 0.4% | Oct 14, 2024 | In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.... |
| CVE-2024-8184 | MEDIUM | 6.5 | 1.0% | Oct 14, 2024 | There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized u... |
| CVE-2024-6763 | MEDIUM | 5.3 | 1.0% | Oct 14, 2024 | Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class,... |
| CVE-2024-6762 | MEDIUM | 6.5 | 0.9% | Oct 14, 2024 | Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the s... |
| CVE-2024-41997 | MEDIUM | 6.6 | 1.2% | Oct 14, 2024 | An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulne... |
| CVE-2024-9936 | MEDIUM | 6.5 | 0.3% | Oct 14, 2024 | When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially lea... |
| CVE-2024-8602 | MEDIUM | 6.3 | 0.4% | Oct 14, 2024 | When the XML is read from the codes in the PDF and parsed using a DocumentBuilder, the default settings of the DocumentB... |
| CVE-2024-48120 | MEDIUM | 5.4 | 0.6% | Oct 14, 2024 | X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject ma... |
| CVE-2024-48119 | MEDIUM | 5.4 | 0.3% | Oct 14, 2024 | Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary H... |
| CVE-2024-46911 | MEDIUM | 4.7 | 0.4% | Oct 14, 2024 | Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now