2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38796 | MEDIUM | 5.9 | 0.4% | Sep 27, 2024 | EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an over... |
| CVE-2024-9291 | MEDIUM | 5.4 | 0.4% | Sep 27, 2024 | A vulnerability classified as problematic has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75... |
| CVE-2024-47186 | MEDIUM | 6.1 | 0.4% | Sep 27, 2024 | Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2... |
| CVE-2024-46453 | MEDIUM | 6.1 | 0.3% | Sep 27, 2024 | A cross-site scripting (XSS) vulnerability in the component /test/ of iq3xcite v2.31 to v3.05 allows attackers to execut... |
| CVE-2024-6436 | MEDIUM | 6.5 | 0.6% | Sep 27, 2024 | An input validation vulnerability exists in the Rockwell Automation Sequence Manager™ which could allow a malicious user... |
| CVE-2024-9160 | MEDIUM | 5.4 | 0.2% | Sep 27, 2024 | In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered. |
| CVE-2024-46257 | MEDIUM | 6.3 | 1.3% | Sep 27, 2024 | A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacke... |
| CVE-2024-38308 | MEDIUM | 6.1 | 0.3% | Sep 27, 2024 | Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the ... |
| CVE-2024-37187 | MEDIUM | 5.7 | 0.4% | Sep 27, 2024 | Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding. |
| CVE-2024-34542 | MEDIUM | 5.7 | 0.2% | Sep 27, 2024 | Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login pr... |
| CVE-2024-25412 | MEDIUM | 6.1 | 0.9% | Sep 27, 2024 | A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML v... |
| CVE-2024-25411 | MEDIUM | 6.1 | 0.7% | Sep 27, 2024 | A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML v... |
| CVE-2024-38809 | MEDIUM | 5.3 | 0.9% | Sep 27, 2024 | Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of... |
| CVE-2024-47077 | MEDIUM | 6.5 | 0.4% | Sep 27, 2024 | authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one appl... |
| CVE-2024-45745 | MEDIUM | 4.3 | 0.3% | Sep 27, 2024 | TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute Jav... |
| CVE-2024-45744 | MEDIUM | 4.3 | 0.2% | Sep 27, 2024 | TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can r... |
| CVE-2024-46470 | MEDIUM | 6.1 | 0.3% | Sep 27, 2024 | Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaS... |
| CVE-2024-46333 | MEDIUM | 4.8 | 0.3% | Sep 27, 2024 | An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web sc... |
| CVE-2024-9283 | MEDIUM | 4.8 | 0.3% | Sep 27, 2024 | A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown functi... |
| CVE-2024-47184 | MEDIUM | 4.8 | 0.5% | Sep 27, 2024 | Ampache is a web based audio/video streaming application and file manager. Prior to version 6.6.0, the Democratic Playli... |
| CVE-2024-45863 | MEDIUM | 5.3 | 0.3% | Sep 27, 2024 | A null-dereference vulnerability involving parsing requests specifying invalid protocols can cause the application to cr... |
| CVE-2024-9282 | MEDIUM | 4.3 | 0.3% | Sep 27, 2024 | A vulnerability was found in bg5sbk MiniCMS 1.11. It has been classified as problematic. Affected is an unknown function... |
| CVE-2024-9281 | MEDIUM | 4.3 | 0.3% | Sep 27, 2024 | A vulnerability was found in bg5sbk MiniCMS up to 1.11 and classified as problematic. This issue affects some unknown pr... |
| CVE-2024-46868 | MEDIUM | 5.5 | 0.1% | Sep 27, 2024 | In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: Fix deadlock in qcuefi_... |
| CVE-2024-46867 | MEDIUM | 5.5 | 0.1% | Sep 27, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/client: fix deadlock in show_meminfo() Ther... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now