2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47565 | MEDIUM | 4.3 | 0.4% | Oct 8, 2024 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not... |
| CVE-2024-47563 | MEDIUM | 5.3 | 0.5% | Oct 8, 2024 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not... |
| CVE-2024-46887 | MEDIUM | 6.9 | 0.5% | Oct 8, 2024 | The web server of affected devices do not properly authenticate user request to the '/ClientArea/RuntimeInfoData.mwsl' e... |
| CVE-2024-46886 | MEDIUM | 5.1 | 0.4% | Oct 8, 2024 | The web server of affected devices does not properly validate input that is used for a user redirection. This could allo... |
| CVE-2024-8964 | MEDIUM | 5.4 | 0.3% | Oct 8, 2024 | The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG Fi... |
| CVE-2024-47095 | MEDIUM | 5.1 | 0.5% | Oct 8, 2024 | Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run... |
| CVE-2024-34671 | MEDIUM | 5.5 | 0.2% | Oct 8, 2024 | Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows l... |
| CVE-2024-34670 | MEDIUM | 5.5 | 0.1% | Oct 8, 2024 | Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to... |
| CVE-2024-34663 | MEDIUM | 5.5 | 0.1% | Oct 8, 2024 | Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory... |
| CVE-2024-9292 | MEDIUM | 6.4 | 0.3% | Oct 8, 2024 | The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions... |
| CVE-2024-9021 | MEDIUM | 5.4 | 0.4% | Oct 8, 2024 | In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to i... |
| CVE-2024-8983 | MEDIUM | 4.8 | 0.4% | Oct 8, 2024 | Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-21533 | MEDIUM | 6.5 | 0.6% | Oct 8, 2024 | All versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specif... |
| CVE-2024-8925 | MEDIUM | 5.3 | 0.9% | Oct 8, 2024 | In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data ... |
| CVE-2024-47594 | MEDIUM | 5.4 | 0.2% | Oct 8, 2024 | SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scrip... |
| CVE-2024-45382 | MEDIUM | 5.5 | 0.1% | Oct 8, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through out-of-bounds write. |
| CVE-2024-45282 | MEDIUM | 5.3 | 0.3% | Oct 8, 2024 | Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified b... |
| CVE-2024-45278 | MEDIUM | 5.4 | 0.2% | Oct 8, 2024 | SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vul... |
| CVE-2024-45277 | MEDIUM | 4.3 | 0.6% | Oct 8, 2024 | The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability ... |
| CVE-2024-43697 | MEDIUM | 5.5 | 0.1% | Oct 8, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input. |
| CVE-2024-43696 | MEDIUM | 5.5 | 0.1% | Oct 8, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak. |
| CVE-2024-39831 | MEDIUM | 6.7 | 0.2% | Oct 8, 2024 | in OpenHarmony v4.1.0 allow a local attacker with high privileges arbitrary code execution in pre-installed apps through... |
| CVE-2024-39806 | MEDIUM | 5.5 | 0.2% | Oct 8, 2024 | in OpenHarmony v4.1.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read. |
| CVE-2024-37179 | MEDIUM | 6.5 | 0.4% | Oct 8, 2024 | SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to t... |
| CVE-2024-47969 | MEDIUM | 6.2 | 0.2% | Oct 7, 2024 | Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially enable denial... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now