2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47968 | MEDIUM | 4.4 | 0.1% | Oct 7, 2024 | Improper resource shutdown in middle of certain operations on some Solidigm DC Products may allow an attacker to potenti... |
| CVE-2024-47818 | MEDIUM | 6.5 | 0.8% | Oct 7, 2024 | Saltcorn is an extensible, open source, no-code database application builder. A logged-in user with any role can delete ... |
| CVE-2024-47817 | MEDIUM | 6.1 | 0.4% | Oct 7, 2024 | Lara-zeus Dynamic Dashboard simple way to manage widgets for your website landing page, and filament dashboard and Lara-... |
| CVE-2024-47814 | MEDIUM | 4.7 | 0.3% | Oct 7, 2024 | Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (vi... |
| CVE-2024-47782 | MEDIUM | 5.4 | 0.3% | Oct 7, 2024 | WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. Special:WikiDiscover is a... |
| CVE-2024-47781 | MEDIUM | 6.1 | 0.3% | Oct 7, 2024 | CreateWiki is an extension used at Miraheze for requesting & creating wikis. The name of requested wikis is not escaped ... |
| CVE-2024-47974 | MEDIUM | 4.4 | 0.1% | Oct 7, 2024 | Race condition during resource shutdown in some Solidigm DC Products may allow an attacker to potentially enable denial ... |
| CVE-2024-47973 | MEDIUM | 5.1 | 0.1% | Oct 7, 2024 | In some Solidigm DC Products, a defect in device overprovisioning may provide information disclosure to an attacker. |
| CVE-2024-47967 | MEDIUM | 4.4 | 0.2% | Oct 7, 2024 | Improper resource initialization handling in firmware of some Solidigm DC Products may allow an attacker to potentially ... |
| CVE-2024-47772 | MEDIUM | 6.1 | 0.3% | Oct 7, 2024 | Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' br... |
| CVE-2024-47610 | MEDIUM | 5.4 | 0.3% | Oct 7, 2024 | InvenTree is an Open Source Inventory Management System. In affected versions of InvenTree it is possible for a register... |
| CVE-2024-45919 | MEDIUM | 6.5 | 0.3% | Oct 7, 2024 | A security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By ma... |
| CVE-2024-45297 | MEDIUM | 4.3 | 0.3% | Oct 7, 2024 | Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the l... |
| CVE-2024-45060 | MEDIUM | 6.1 | 0.5% | Oct 7, 2024 | PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. One of the sample scripts in PhpSpreadsh... |
| CVE-2024-43789 | MEDIUM | 4.3 | 0.4% | Oct 7, 2024 | Discourse is an open source platform for community discussion. A user can create a post with many replies, and then atte... |
| CVE-2024-43362 | MEDIUM | 5.4 | 35.5% | Oct 7, 2024 | Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized wh... |
| CVE-2024-47976 | MEDIUM | 6.7 | 0.2% | Oct 7, 2024 | Improper access removal handling in firmware of some Solidigm DC Products may allow an attacker with physical access to ... |
| CVE-2024-47972 | MEDIUM | 4 | 0.2% | Oct 7, 2024 | Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially control the p... |
| CVE-2024-47971 | MEDIUM | 6.5 | 0.1% | Oct 7, 2024 | Improper error handling in firmware of some SSD DC Products may allow an attacker to enable denial of service. |
| CVE-2024-47079 | MEDIUM | 6.4 | 0.2% | Oct 7, 2024 | Meshtastic is an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Mesht... |
| CVE-2024-45292 | MEDIUM | 5.4 | 0.3% | Oct 7, 2024 | PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. `\PhpOffice\PhpSpreadsheet\Writer\Html` ... |
| CVE-2024-31228 | MEDIUM | 6.5 | 1.0% | Oct 7, 2024 | Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service b... |
| CVE-2024-31227 | MEDIUM | 4.4 | 0.4% | Oct 7, 2024 | Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may creat... |
| CVE-2024-45894 | MEDIUM | 4.9 | 0.3% | Oct 7, 2024 | BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request. |
| CVE-2024-44674 | MEDIUM | 5.7 | 3.9% | Oct 7, 2024 | D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained thr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now