2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41587 | MEDIUM | 5.4 | 0.2% | Oct 3, 2024 | Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor31... |
| CVE-2024-41585 | MEDIUM | 6.8 | 0.8% | Oct 3, 2024 | DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker ... |
| CVE-2024-41584 | MEDIUM | 4.7 | 0.3% | Oct 3, 2024 | DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing vali... |
| CVE-2024-41583 | MEDIUM | 4.7 | 0.3% | Oct 3, 2024 | DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to stored Cross Site Scripting (XSS) by authenticated users due... |
| CVE-2024-47762 | MEDIUM | 5.8 | 0.4% | Oct 3, 2024 | Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment v... |
| CVE-2024-34535 | MEDIUM | 5.9 | 0.4% | Oct 3, 2024 | In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header. |
| CVE-2024-8508 | MEDIUM | 5.3 | 0.8% | Oct 3, 2024 | NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRs... |
| CVE-2024-45872 | MEDIUM | 6.3 | 0.4% | Oct 3, 2024 | Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient... |
| CVE-2024-45871 | MEDIUM | 6.3 | 0.4% | Oct 3, 2024 | Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS). |
| CVE-2024-45870 | MEDIUM | 6.5 | 0.4% | Oct 3, 2024 | Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file. |
| CVE-2024-9100 | MEDIUM | 6.5 | 0.5% | Oct 3, 2024 | Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnera... |
| CVE-2024-47618 | MEDIUM | 5.4 | 0.4% | Oct 3, 2024 | Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the... |
| CVE-2024-47617 | MEDIUM | 6.1 | 0.3% | Oct 3, 2024 | Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code ... |
| CVE-2024-47554 | MEDIUM | 4.3 | 1.2% | Oct 3, 2024 | Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader c... |
| CVE-2024-42504 | MEDIUM | 4.3 | 0.1% | Oct 3, 2024 | A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery... |
| CVE-2024-8159 | MEDIUM | 6.4 | 0.2% | Oct 3, 2024 | Deep Freeze 9.00.020.5760 is vulnerable to an out-of-bounds read vulnerability by triggering the 0x70014 IOCTL code of t... |
| CVE-2024-47616 | MEDIUM | 6.8 | 0.6% | Oct 2, 2024 | Pomerium is an identity and context-aware access proxy. The Pomerium databroker service is responsible for managing all ... |
| CVE-2024-47529 | MEDIUM | 6.5 | 0.3% | Oct 2, 2024 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2024-46977 | MEDIUM | 6.5 | 0.9% | Oct 2, 2024 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2024-45965 | MEDIUM | 5.4 | 0.3% | Oct 2, 2024 | Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54,... |
| CVE-2024-45964 | MEDIUM | 4.8 | 0.3% | Oct 2, 2024 | Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field. |
| CVE-2024-45962 | MEDIUM | 4.7 | 0.5% | Oct 2, 2024 | October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the targe... |
| CVE-2024-45960 | MEDIUM | 4.8 | 0.3% | Oct 2, 2024 | Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system.... |
| CVE-2024-43795 | MEDIUM | 6.1 | 0.4% | Oct 2, 2024 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2024-9440 | MEDIUM | 6.1 | 0.4% | Oct 2, 2024 | Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability. In select.ts:crea... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now