2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38817 | MEDIUM | 6.7 | 0.5% | Oct 9, 2024 | VMware NSX contains a command injection vulnerability. A malicious actor with access to the NSX Edge CLI terminal may ... |
| CVE-2024-38815 | MEDIUM | 4.3 | 0.3% | Oct 9, 2024 | VMware NSX contains a content spoofing vulnerability. An unauthenticated malicious actor may be able to craft a URL an... |
| CVE-2024-30118 | MEDIUM | 5.7 | 0.3% | Oct 9, 2024 | HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive in... |
| CVE-2024-47833 | MEDIUM | 6.5 | 0.2% | Oct 9, 2024 | Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine lear... |
| CVE-2024-47828 | MEDIUM | 6.5 | 0.3% | Oct 9, 2024 | ampache is a web based audio/video streaming application and file manager. A CSRF attack can be performed in order to de... |
| CVE-2024-47816 | MEDIUM | 6.4 | 0.3% | Oct 9, 2024 | ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the ... |
| CVE-2024-47815 | MEDIUM | 6 | 0.4% | Oct 9, 2024 | IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a var... |
| CVE-2024-47812 | MEDIUM | 6 | 0.4% | Oct 9, 2024 | ImportDump is an extension for mediawiki designed to automate user import requests. Anyone who can edit the interface st... |
| CVE-2024-47763 | MEDIUM | 5.5 | 0.2% | Oct 9, 2024 | Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of WebAssembly tail calls combined with st... |
| CVE-2024-9471 | MEDIUM | 4.7 | 0.3% | Oct 9, 2024 | A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated ... |
| CVE-2024-9470 | MEDIUM | 5.3 | 0.4% | Oct 9, 2024 | A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view th... |
| CVE-2024-9469 | MEDIUM | 5.5 | 0.2% | Oct 9, 2024 | A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with W... |
| CVE-2024-9467 | MEDIUM | 6.1 | 0.6% | Oct 9, 2024 | A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context ... |
| CVE-2024-9466 | MEDIUM | 6.5 | 11.2% | Oct 9, 2024 | A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated atta... |
| CVE-2024-9464 | MEDIUM | 6.5 | 81.7% | Oct 9, 2024 | An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary... |
| CVE-2024-42988 | MEDIUM | 4.3 | 0.3% | Oct 9, 2024 | Lack of access control in ChallengeSolves (/api/v1/challenges/<challenge id>/solves) of CTFd v2.0.0 - v3.7.2 allows auth... |
| CVE-2024-9675 | MEDIUM | 4.4 | 0.4% | Oct 9, 2024 | A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are ... |
| CVE-2024-9671 | MEDIUM | 5.3 | 0.3% | Oct 9, 2024 | A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is k... |
| CVE-2024-7294 | MEDIUM | 6.5 | 0.3% | Oct 9, 2024 | In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous... |
| CVE-2024-47673 | MEDIUM | 5.5 | 0.2% | Oct 9, 2024 | In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: pause TCM when the firmware is ... |
| CVE-2024-47671 | MEDIUM | 5.5 | 0.2% | Oct 9, 2024 | In the Linux kernel, the following vulnerability has been resolved: USB: usbtmc: prevent kernel-usb-infoleak The syzbo... |
| CVE-2024-47669 | MEDIUM | 5.5 | 0.2% | Oct 9, 2024 | In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix state management in error path of log w... |
| CVE-2024-47668 | MEDIUM | 4.7 | 0.2% | Oct 9, 2024 | In the Linux kernel, the following vulnerability has been resolved: lib/generic-radix-tree.c: Fix rare race in __genrad... |
| CVE-2024-47667 | MEDIUM | 5.5 | 0.2% | Oct 9, 2024 | In the Linux kernel, the following vulnerability has been resolved: PCI: keystone: Add workaround for Errata #i2037 (AM... |
| CVE-2024-47666 | MEDIUM | 5.5 | 0.2% | Oct 9, 2024 | In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Set phy->enable_completion only when ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now