2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45741 | MEDIUM | 5.4 | 12.9% | Oct 14, 2024 | In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.2... |
| CVE-2024-45740 | MEDIUM | 5.4 | 0.4% | Oct 14, 2024 | In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403, a low-privileged ... |
| CVE-2024-45739 | MEDIUM | 4.9 | 0.5% | Oct 14, 2024 | In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for lo... |
| CVE-2024-45738 | MEDIUM | 4.9 | 0.5% | Oct 14, 2024 | In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters ... |
| CVE-2024-45736 | MEDIUM | 6.5 | 0.5% | Oct 14, 2024 | In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2... |
| CVE-2024-45735 | MEDIUM | 4.3 | 0.3% | Oct 14, 2024 | In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform version... |
| CVE-2024-45734 | MEDIUM | 4.3 | 0.3% | Oct 14, 2024 | In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" S... |
| CVE-2024-45732 | MEDIUM | 6.5 | 0.4% | Oct 14, 2024 | In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.... |
| CVE-2024-8184 | MEDIUM | 6.5 | 1.0% | Oct 14, 2024 | There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized u... |
| CVE-2024-6763 | MEDIUM | 5.3 | 1.0% | Oct 14, 2024 | Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class,... |
| CVE-2024-6762 | MEDIUM | 6.5 | 0.9% | Oct 14, 2024 | Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the s... |
| CVE-2024-41997 | MEDIUM | 6.6 | 1.2% | Oct 14, 2024 | An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulne... |
| CVE-2024-9936 | MEDIUM | 6.5 | 0.3% | Oct 14, 2024 | When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially lea... |
| CVE-2024-8602 | MEDIUM | 6.3 | 0.4% | Oct 14, 2024 | When the XML is read from the codes in the PDF and parsed using a DocumentBuilder, the default settings of the DocumentB... |
| CVE-2024-48120 | MEDIUM | 5.4 | 0.6% | Oct 14, 2024 | X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject ma... |
| CVE-2024-48119 | MEDIUM | 5.4 | 0.3% | Oct 14, 2024 | Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary H... |
| CVE-2024-46911 | MEDIUM | 4.7 | 0.4% | Oct 14, 2024 | Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websi... |
| CVE-2024-38862 | MEDIUM | 4.4 | 0.3% | Oct 14, 2024 | Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35, <2.1.0p48 and ... |
| CVE-2024-9923 | MEDIUM | 4.9 | 0.6% | Oct 14, 2024 | The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with ... |
| CVE-2024-49214 | MEDIUM | 5.3 | 0.5% | Oct 14, 2024 | QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a... |
| CVE-2024-9917 | MEDIUM | 4.9 | 8.7% | Oct 13, 2024 | A vulnerability, which was classified as critical, was found in HuangDou UTCMS V9. This affects an unknown part of the f... |
| CVE-2024-9907 | MEDIUM | 6.3 | 0.4% | Oct 13, 2024 | A vulnerability classified as problematic was found in QileCMS up to 1.1.3. This vulnerability affects the function send... |
| CVE-2024-9906 | MEDIUM | 5.4 | 0.4% | Oct 13, 2024 | A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is a... |
| CVE-2024-8902 | MEDIUM | 4.3 | 0.4% | Oct 12, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,... |
| CVE-2024-9696 | MEDIUM | 5.4 | 0.2% | Oct 12, 2024 | The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rescue_tab' sh... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now