2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47976 | MEDIUM | 6.7 | 0.2% | Oct 7, 2024 | Improper access removal handling in firmware of some Solidigm DC Products may allow an attacker with physical access to ... |
| CVE-2024-47972 | MEDIUM | 4 | 0.2% | Oct 7, 2024 | Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially control the p... |
| CVE-2024-47971 | MEDIUM | 6.5 | 0.1% | Oct 7, 2024 | Improper error handling in firmware of some SSD DC Products may allow an attacker to enable denial of service. |
| CVE-2024-47079 | MEDIUM | 6.4 | 0.2% | Oct 7, 2024 | Meshtastic is an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Mesht... |
| CVE-2024-45292 | MEDIUM | 5.4 | 0.3% | Oct 7, 2024 | PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. `\PhpOffice\PhpSpreadsheet\Writer\Html` ... |
| CVE-2024-31228 | MEDIUM | 6.5 | 1.0% | Oct 7, 2024 | Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service b... |
| CVE-2024-31227 | MEDIUM | 4.4 | 0.4% | Oct 7, 2024 | Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may creat... |
| CVE-2024-45894 | MEDIUM | 4.9 | 0.3% | Oct 7, 2024 | BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request. |
| CVE-2024-44674 | MEDIUM | 5.7 | 3.9% | Oct 7, 2024 | D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained thr... |
| CVE-2024-42831 | MEDIUM | 6.1 | 1.1% | Oct 7, 2024 | A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to ex... |
| CVE-2024-46300 | MEDIUM | 6.1 | 0.4% | Oct 7, 2024 | itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in regi... |
| CVE-2024-46040 | MEDIUM | 6.5 | 0.3% | Oct 7, 2024 | IoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S v5.16.1 suffers from Insufficient Session Expiration. The lack of validation... |
| CVE-2024-45932 | MEDIUM | 4.8 | 0.4% | Oct 7, 2024 | Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organiz... |
| CVE-2024-28710 | MEDIUM | 6.1 | 0.5% | Oct 7, 2024 | Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code ... |
| CVE-2024-28709 | MEDIUM | 6.1 | 0.5% | Oct 7, 2024 | Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code... |
| CVE-2024-9574 | MEDIUM | 6.5 | 0.5% | Oct 7, 2024 | SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could a... |
| CVE-2024-9573 | MEDIUM | 6.5 | 0.3% | Oct 7, 2024 | SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which cou... |
| CVE-2024-9572 | MEDIUM | 5.4 | 0.3% | Oct 7, 2024 | Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplan... |
| CVE-2024-9571 | MEDIUM | 5.4 | 0.3% | Oct 7, 2024 | Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplan... |
| CVE-2024-45933 | MEDIUM | 6.6 | 0.2% | Oct 7, 2024 | OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the... |
| CVE-2024-46325 | MEDIUM | 5.5 | 0.2% | Oct 7, 2024 | TP-Link WR740N V6 has a stack overflow vulnerability via the ssid parameter in /userRpm/popupSiteSurveyRpm.htm url. |
| CVE-2024-45153 | MEDIUM | 5.4 | 0.4% | Oct 7, 2024 | Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-42027 | MEDIUM | 6.7 | 0.5% | Oct 7, 2024 | The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to ... |
| CVE-2024-38425 | MEDIUM | 6.1 | 0.1% | Oct 7, 2024 | Information disclosure while sending implicit broadcast containing APP launch information. |
| CVE-2024-23379 | MEDIUM | 6.7 | 0.1% | Oct 7, 2024 | Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now