2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47178 | MEDIUM | 5.3 | 0.5% | Sep 30, 2024 | basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe... |
| CVE-2024-47067 | MEDIUM | 6.1 | 0.4% | Sep 30, 2024 | AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerabil... |
| CVE-2024-46869 | MEDIUM | 5.5 | 0.2% | Sep 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: Allocate memory for driver... |
| CVE-2024-46475 | MEDIUM | 4.8 | 0.3% | Sep 30, 2024 | A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows at... |
| CVE-2024-47172 | MEDIUM | 5.4 | 0.3% | Sep 30, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacke... |
| CVE-2024-47064 | MEDIUM | 6.1 | 0.3% | Sep 30, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an atta... |
| CVE-2024-47063 | MEDIUM | 6.1 | 0.3% | Sep 30, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If a malic... |
| CVE-2024-45792 | MEDIUM | 6.5 | 0.5% | Sep 30, 2024 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered... |
| CVE-2024-6051 | MEDIUM | 4.3 | 0.2% | Sep 30, 2024 | Cross Application Scripting vulnerability in Vercom S.A. Redlink SDK in specific situations allows local code injection ... |
| CVE-2024-47641 | MEDIUM | 6.5 | 0.2% | Sep 30, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Muhammad Shakeel C... |
| CVE-2024-45920 | MEDIUM | 5.4 | 0.3% | Sep 30, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability in Solvait 24.4.2 allows remote attackers to inject malicious scripts ... |
| CVE-2024-9329 | MEDIUM | 6.1 | 0.7% | Sep 30, 2024 | In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the ... |
| CVE-2024-8459 | MEDIUM | 4.9 | 0.3% | Sep 30, 2024 | Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, ... |
| CVE-2024-8457 | MEDIUM | 4.8 | 0.3% | Sep 30, 2024 | Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters,... |
| CVE-2024-8455 | MEDIUM | 5.9 | 0.3% | Sep 30, 2024 | The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authe... |
| CVE-2024-8453 | MEDIUM | 4.9 | 0.3% | Sep 30, 2024 | Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salte... |
| CVE-2024-45200 | MEDIUM | 6.3 | 1.4% | Sep 30, 2024 | In Nintendo Mario Kart 8 Deluxe before 3.0.3, the LAN/LDN local multiplayer implementation allows a remote attacker to e... |
| CVE-2024-41999 | MEDIUM | 6.8 | 0.3% | Sep 30, 2024 | Smart-tab Android app installed April 2023 or earlier contains an active debug code vulnerability. If this vulnerability... |
| CVE-2024-8449 | MEDIUM | 6.8 | 0.3% | Sep 30, 2024 | Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allo... |
| CVE-2024-8536 | MEDIUM | 5.4 | 0.3% | Sep 30, 2024 | The Ultimate Blocks WordPress plugin before 3.2.2 does not validate and escape some of its block attributes before outp... |
| CVE-2024-8283 | MEDIUM | 4.8 | 0.4% | Sep 30, 2024 | The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow... |
| CVE-2024-8239 | MEDIUM | 5.4 | 0.3% | Sep 30, 2024 | The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like... |
| CVE-2024-3635 | MEDIUM | 4.8 | 0.3% | Sep 30, 2024 | The Post Grid WordPress plugin before 7.5.0 does not sanitise and escape some of its Grid settings, which could allow h... |
| CVE-2024-9323 | MEDIUM | 5.4 | 0.4% | Sep 29, 2024 | A vulnerability was found in SourceCodester Inventory Management System 1.0. It has been declared as problematic. Affect... |
| CVE-2024-9321 | MEDIUM | 5.3 | 0.6% | Sep 29, 2024 | A vulnerability was found in SourceCodester Online Railway Reservation System 1.0 and classified as critical. This issue... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now