2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-44540 | MEDIUM | 6.6 | 0.2% | Sep 23, 2024 | Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command s... |
| CVE-2024-43201 | MEDIUM | 5.9 | 0.4% | Sep 23, 2024 | The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker... |
| CVE-2024-39843 | MEDIUM | 6.7 | 2.1% | Sep 23, 2024 | A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL comm... |
| CVE-2024-39342 | MEDIUM | 6.6 | 0.1% | Sep 23, 2024 | Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier use... |
| CVE-2024-39341 | MEDIUM | 5.9 | 0.2% | Sep 23, 2024 | Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and... |
| CVE-2024-9014 | MEDIUM | 6.5 | 9.7% | Sep 23, 2024 | pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows ... |
| CVE-2024-40441 | MEDIUM | 6.6 | 0.6% | Sep 23, 2024 | An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pi... |
| CVE-2024-47069 | MEDIUM | 6.1 | 0.4% | Sep 23, 2024 | Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy set... |
| CVE-2024-47068 | MEDIUM | 6.1 | 0.7% | Sep 23, 2024 | Rollup is a module bundler for JavaScript. Versions prior to 2.79.2, 3.29.5, and 4.22.4 are susceptible to a DOM Clobber... |
| CVE-2024-23972 | MEDIUM | 6.8 | 0.8% | Sep 23, 2024 | Sony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution Vulnerability. This vulnerability all... |
| CVE-2024-23933 | MEDIUM | 6.8 | 0.7% | Sep 23, 2024 | Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows p... |
| CVE-2024-23922 | MEDIUM | 6.8 | 1.7% | Sep 23, 2024 | Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows p... |
| CVE-2024-46241 | MEDIUM | 5.9 | 0.2% | Sep 23, 2024 | PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in... |
| CVE-2024-46544 | MEDIUM | 5.9 | 0.3% | Sep 23, 2024 | Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared mem... |
| CVE-2024-8903 | MEDIUM | 4.7 | 0.1% | Sep 23, 2024 | Local active protection service settings manipulation due to unnecessary privileges assignment. The following products a... |
| CVE-2024-8758 | MEDIUM | 4.8 | 0.4% | Sep 23, 2024 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which... |
| CVE-2024-7846 | MEDIUM | 5.4 | 0.3% | Sep 23, 2024 | YITH WooCommerce Ajax Search is vulnerable to a XSS vulnerability due to insufficient sanitization of user supplied bloc... |
| CVE-2024-47227 | MEDIUM | 6.1 | 0.3% | Sep 23, 2024 | iRedAdmin before 2.6 allows XSS, e.g., via order_name. |
| CVE-2024-9092 | MEDIUM | 6.1 | 0.4% | Sep 23, 2024 | A vulnerability was found in SourceCodester Profile Registration without Reload Refresh 1.0. It has been rated as proble... |
| CVE-2024-44048 | MEDIUM | 6.5 | 0.5% | Sep 23, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-43996 | MEDIUM | 6.5 | 0.6% | Sep 23, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit ... |
| CVE-2024-9089 | MEDIUM | 5.4 | 0.4% | Sep 23, 2024 | A vulnerability was found in SourceCodester Modern Loan Management System 1.0 and classified as problematic. This issue ... |
| CVE-2024-40703 | MEDIUM | 5.5 | 0.1% | Sep 22, 2024 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and IBM Cognos Analytics Re... |
| CVE-2024-9084 | MEDIUM | 5.4 | 0.4% | Sep 22, 2024 | A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects u... |
| CVE-2024-9083 | MEDIUM | 4.8 | 0.4% | Sep 22, 2024 | A vulnerability classified as problematic has been found in SourceCodester Employee Management System 1.0. This affects ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now