2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37879 | MEDIUM | 4.8 | 0.4% | Sep 20, 2024 | Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrato... |
| CVE-2024-9036 | MEDIUM | 6.3 | 0.5% | Sep 20, 2024 | A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some u... |
| CVE-2024-9033 | MEDIUM | 5.4 | 0.4% | Sep 20, 2024 | A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. ... |
| CVE-2024-9031 | MEDIUM | 5.4 | 0.3% | Sep 20, 2024 | A vulnerability, which was classified as problematic, has been found in CodeCanyon CRMGo SaaS up to 7.2. This issue affe... |
| CVE-2024-9030 | MEDIUM | 5.4 | 0.3% | Sep 20, 2024 | A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2. This vulnerability affects unknown cod... |
| CVE-2024-47060 | MEDIUM | 6.5 | 0.4% | Sep 20, 2024 | Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associate... |
| CVE-2024-46999 | MEDIUM | 6.5 | 0.3% | Sep 20, 2024 | Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correc... |
| CVE-2024-45808 | MEDIUM | 6.5 | 0.4% | Sep 20, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that al... |
| CVE-2024-45806 | MEDIUM | 6.5 | 0.4% | Sep 20, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external cl... |
| CVE-2024-9007 | MEDIUM | 5.4 | 0.9% | Sep 19, 2024 | A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of... |
| CVE-2024-45614 | MEDIUM | 5.4 | 0.7% | Sep 19, 2024 | Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermedi... |
| CVE-2024-9003 | MEDIUM | 5.3 | 0.3% | Sep 19, 2024 | A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects th... |
| CVE-2024-38221 | MEDIUM | 4.3 | 0.5% | Sep 19, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-25673 | MEDIUM | 6.1 | 0.3% | Sep 19, 2024 | Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection. |
| CVE-2024-47162 | MEDIUM | 5.3 | 0.3% | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page |
| CVE-2024-47160 | MEDIUM | 5.3 | 0.4% | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible |
| CVE-2024-47159 | MEDIUM | 4.3 | 0.3% | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a pro... |
| CVE-2024-8653 | MEDIUM | 6.1 | 0.3% | Sep 19, 2024 | A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific... |
| CVE-2024-8652 | MEDIUM | 6.1 | 0.3% | Sep 19, 2024 | A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific... |
| CVE-2024-8651 | MEDIUM | 5.3 | 0.4% | Sep 19, 2024 | A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whet... |
| CVE-2024-8883 | MEDIUM | 6.1 | 2.0% | Sep 19, 2024 | A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if... |
| CVE-2024-7736 | MEDIUM | 5.4 | 0.3% | Sep 19, 2024 | A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEX... |
| CVE-2024-8354 | MEDIUM | 5.5 | 0.3% | Sep 19, 2024 | A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to ... |
| CVE-2024-45770 | MEDIUM | 4.4 | 0.3% | Sep 19, 2024 | A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a ... |
| CVE-2024-45769 | MEDIUM | 5.5 | 0.3% | Sep 19, 2024 | A vulnerability was found in Performance Co-Pilot (PCP). This flaw allows an attacker to send specially crafted data to... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now