2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45870 | MEDIUM | 6.5 | 0.4% | Oct 3, 2024 | Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file. |
| CVE-2024-9100 | MEDIUM | 6.5 | 0.5% | Oct 3, 2024 | Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnera... |
| CVE-2024-47618 | MEDIUM | 5.4 | 0.4% | Oct 3, 2024 | Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the... |
| CVE-2024-47617 | MEDIUM | 6.1 | 0.3% | Oct 3, 2024 | Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code ... |
| CVE-2024-47554 | MEDIUM | 4.3 | 1.2% | Oct 3, 2024 | Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader c... |
| CVE-2024-42504 | MEDIUM | 4.3 | 0.1% | Oct 3, 2024 | A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery... |
| CVE-2024-8159 | MEDIUM | 6.4 | 0.2% | Oct 3, 2024 | Deep Freeze 9.00.020.5760 is vulnerable to an out-of-bounds read vulnerability by triggering the 0x70014 IOCTL code of t... |
| CVE-2024-47616 | MEDIUM | 6.8 | 0.6% | Oct 2, 2024 | Pomerium is an identity and context-aware access proxy. The Pomerium databroker service is responsible for managing all ... |
| CVE-2024-47529 | MEDIUM | 6.5 | 0.3% | Oct 2, 2024 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2024-46977 | MEDIUM | 6.5 | 0.9% | Oct 2, 2024 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2024-45965 | MEDIUM | 5.4 | 0.3% | Oct 2, 2024 | Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54,... |
| CVE-2024-45964 | MEDIUM | 4.8 | 0.3% | Oct 2, 2024 | Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field. |
| CVE-2024-45962 | MEDIUM | 4.7 | 0.5% | Oct 2, 2024 | October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the targe... |
| CVE-2024-45960 | MEDIUM | 4.8 | 0.3% | Oct 2, 2024 | Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system.... |
| CVE-2024-43795 | MEDIUM | 6.1 | 0.4% | Oct 2, 2024 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2024-9440 | MEDIUM | 6.1 | 0.4% | Oct 2, 2024 | Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability. In select.ts:crea... |
| CVE-2024-20513 | MEDIUM | 5.3 | 0.5% | Oct 2, 2024 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devic... |
| CVE-2024-20509 | MEDIUM | 5.9 | 0.4% | Oct 2, 2024 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devic... |
| CVE-2024-20524 | MEDIUM | 6.8 | 0.5% | Oct 2, 2024 | A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers co... |
| CVE-2024-20523 | MEDIUM | 6.8 | 0.5% | Oct 2, 2024 | A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers co... |
| CVE-2024-20522 | MEDIUM | 6.8 | 0.5% | Oct 2, 2024 | A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers co... |
| CVE-2024-20517 | MEDIUM | 6.8 | 0.4% | Oct 2, 2024 | A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers co... |
| CVE-2024-20516 | MEDIUM | 6.8 | 0.4% | Oct 2, 2024 | A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers co... |
| CVE-2024-20515 | MEDIUM | 6.5 | 0.3% | Oct 2, 2024 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2024-20492 | MEDIUM | 6.7 | 0.5% | Oct 2, 2024 | A vulnerability in the restricted shell of Cisco Expressway Series could allow an authenticated, local attacker to perfo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now