2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48040 | MEDIUM | 6.5 | 0.5% | Oct 11, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan ... |
| CVE-2024-47353 | MEDIUM | 6.1 | 0.2% | Oct 11, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in quomodosoft ElementsReady Addons for Elementor elem... |
| CVE-2024-9539 | MEDIUM | 4.3 | 0.6% | Oct 11, 2024 | An information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allow... |
| CVE-2024-44807 | MEDIUM | 5.3 | 0.5% | Oct 11, 2024 | A directory listing issue in the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition befor... |
| CVE-2024-44157 | MEDIUM | 5.5 | 0.2% | Oct 11, 2024 | A stack buffer overflow was addressed through improved input validation. This issue is fixed in Apple TV 1.5.0.152 for W... |
| CVE-2024-46215 | MEDIUM | 6.5 | 2.9% | Oct 11, 2024 | A vulnerability was discovered in KM08-708H-v1.1, There is a buffer overflow in the sub_445BDC() function within the /us... |
| CVE-2024-44731 | MEDIUM | 4.7 | 0.4% | Oct 11, 2024 | Mirotalk before commit 9de226 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allow... |
| CVE-2024-44415 | MEDIUM | 6.5 | 0.3% | Oct 11, 2024 | A vulnerability was discovered in DI_8200-16.07.26A1, There is a buffer overflow in the dbsrv_asp function; The strcpy f... |
| CVE-2024-6985 | MEDIUM | 4.4 | 0.4% | Oct 11, 2024 | A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms-webui. This vulnera... |
| CVE-2024-5474 | MEDIUM | 5.5 | 0.1% | Oct 11, 2024 | A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning softwar... |
| CVE-2024-47507 | MEDIUM | 6.9 | 0.3% | Oct 11, 2024 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Ne... |
| CVE-2024-47501 | MEDIUM | 6.8 | 0.2% | Oct 11, 2024 | A NULL Pointer Dereference vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX304, ... |
| CVE-2024-47496 | MEDIUM | 6.8 | 0.2% | Oct 11, 2024 | A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a loc... |
| CVE-2024-47489 | MEDIUM | 6.9 | 0.6% | Oct 11, 2024 | An Improper Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of the Juniper Networ... |
| CVE-2024-39544 | MEDIUM | 5.1 | 0.2% | Oct 11, 2024 | An Incorrect Default Permissions vulnerability in the command line interface (CLI) of Juniper Networks Junos OS Evolved ... |
| CVE-2024-39534 | MEDIUM | 5.4 | 0.6% | Oct 11, 2024 | An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks Junos OS Evolved allows ... |
| CVE-2024-39527 | MEDIUM | 6.8 | 0.2% | Oct 11, 2024 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Junip... |
| CVE-2024-47875 | MEDIUM | 6.1 | 1.1% | Oct 11, 2024 | DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to n... |
| CVE-2024-47830 | MEDIUM | 5.8 | 0.6% | Oct 11, 2024 | Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostn... |
| CVE-2024-25622 | MEDIUM | 4.3 | 0.4% | Oct 11, 2024 | h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The configuration directives provided by the headers... |
| CVE-2024-8530 | MEDIUM | 5.9 | 0.5% | Oct 11, 2024 | CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data whe... |
| CVE-2024-6657 | MEDIUM | 6.5 | 0.2% | Oct 11, 2024 | A denial of service may be caused to a single peripheral device in a BLE network when multiple central devices continuo... |
| CVE-2024-9856 | MEDIUM | 4.8 | 0.4% | Oct 11, 2024 | A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this ... |
| CVE-2024-9616 | MEDIUM | 6.1 | 0.4% | Oct 11, 2024 | The BlockMeister – Block Pattern Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the... |
| CVE-2024-9611 | MEDIUM | 6.1 | 0.4% | Oct 11, 2024 | The Increase upload file size & Maximum Execution Time limit plugin for WordPress is vulnerable to Reflected Cross-Site ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now