2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-46635 | MEDIUM | 5.9 | 0.3% | Sep 30, 2024 | An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access se... |
| CVE-2024-35495 | MEDIUM | 4.3 | 0.2% | Sep 30, 2024 | An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Bu... |
| CVE-2024-9158 | MEDIUM | 4.6 | 0.3% | Sep 30, 2024 | A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local at... |
| CVE-2024-47536 | MEDIUM | 5.4 | 0.4% | Sep 30, 2024 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo rig... |
| CVE-2024-46548 | MEDIUM | 6.3 | 0.1% | Sep 30, 2024 | TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eave... |
| CVE-2024-46540 | MEDIUM | 6.3 | 0.7% | Sep 30, 2024 | A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attacke... |
| CVE-2024-45993 | MEDIUM | 6.5 | 0.5% | Sep 30, 2024 | Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb. |
| CVE-2024-47532 | MEDIUM | 6.5 | 0.7% | Sep 30, 2024 | RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to prote... |
| CVE-2024-47530 | MEDIUM | 6.1 | 0.4% | Sep 30, 2024 | Scout is a web-based visualizer for VCF-files. Open redirect vulnerability allows performing phishing attacks on users b... |
| CVE-2024-47178 | MEDIUM | 5.3 | 0.5% | Sep 30, 2024 | basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe... |
| CVE-2024-47067 | MEDIUM | 6.1 | 0.4% | Sep 30, 2024 | AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerabil... |
| CVE-2024-46869 | MEDIUM | 5.5 | 0.2% | Sep 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: Allocate memory for driver... |
| CVE-2024-46475 | MEDIUM | 4.8 | 0.3% | Sep 30, 2024 | A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows at... |
| CVE-2024-47172 | MEDIUM | 5.4 | 0.3% | Sep 30, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacke... |
| CVE-2024-47064 | MEDIUM | 6.1 | 0.3% | Sep 30, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an atta... |
| CVE-2024-47063 | MEDIUM | 6.1 | 0.3% | Sep 30, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If a malic... |
| CVE-2024-45792 | MEDIUM | 6.5 | 0.5% | Sep 30, 2024 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered... |
| CVE-2024-6051 | MEDIUM | 4.3 | 0.2% | Sep 30, 2024 | Cross Application Scripting vulnerability in Vercom S.A. Redlink SDK in specific situations allows local code injection ... |
| CVE-2024-47641 | MEDIUM | 6.5 | 0.2% | Sep 30, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Muhammad Shakeel C... |
| CVE-2024-45920 | MEDIUM | 5.4 | 0.3% | Sep 30, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability in Solvait 24.4.2 allows remote attackers to inject malicious scripts ... |
| CVE-2024-9329 | MEDIUM | 6.1 | 0.7% | Sep 30, 2024 | In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the ... |
| CVE-2024-8459 | MEDIUM | 4.9 | 0.3% | Sep 30, 2024 | Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, ... |
| CVE-2024-8457 | MEDIUM | 4.8 | 0.3% | Sep 30, 2024 | Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters,... |
| CVE-2024-8455 | MEDIUM | 5.9 | 0.3% | Sep 30, 2024 | The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authe... |
| CVE-2024-8453 | MEDIUM | 4.9 | 0.3% | Sep 30, 2024 | Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salte... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now