2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9077 | MEDIUM | 5.4 | 0.5% | Sep 22, 2024 | A vulnerability classified as problematic has been found in dingfangzu up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. A... |
| CVE-2024-47226 | MEDIUM | 5.4 | 0.3% | Sep 22, 2024 | A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of t... |
| CVE-2024-9075 | MEDIUM | 5.4 | 0.4% | Sep 21, 2024 | A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3. It has been declared as problematic. This vulnera... |
| CVE-2024-9048 | MEDIUM | 6.1 | 0.4% | Sep 21, 2024 | A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerab... |
| CVE-2024-8680 | MEDIUM | 5.5 | 0.5% | Sep 21, 2024 | The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings ... |
| CVE-2024-6787 | MEDIUM | 5.9 | 0.3% | Sep 21, 2024 | This vulnerability occurs when an attacker exploits a race condition between the time a file is checked and the time it ... |
| CVE-2024-6786 | MEDIUM | 6.5 | 0.5% | Sep 21, 2024 | The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling the... |
| CVE-2024-46647 | MEDIUM | 6.5 | 0.8% | Sep 20, 2024 | eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files. |
| CVE-2024-46646 | MEDIUM | 6.5 | 0.8% | Sep 20, 2024 | eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file. |
| CVE-2024-46644 | MEDIUM | 6.5 | 0.8% | Sep 20, 2024 | eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file. |
| CVE-2024-45793 | MEDIUM | 4.8 | 0.3% | Sep 20, 2024 | Confidant is a open source secret management service that provides user-friendly storage and access to secrets. The foll... |
| CVE-2024-46654 | MEDIUM | 4.8 | 0.2% | Sep 20, 2024 | A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows at... |
| CVE-2024-45229 | MEDIUM | 6.6 | 0.5% | Sep 20, 2024 | The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the login screen,... |
| CVE-2024-42346 | MEDIUM | 5.4 | 0.7% | Sep 20, 2024 | Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, ... |
| CVE-2024-42697 | MEDIUM | 6.1 | 0.3% | Sep 20, 2024 | Cross Site Scripting vulnerability in Leotheme Leo Product Search Module v.2.1.6 and earlier allows a remote attacker to... |
| CVE-2024-9040 | MEDIUM | 5.5 | 0.2% | Sep 20, 2024 | A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This ... |
| CVE-2024-37879 | MEDIUM | 4.8 | 0.4% | Sep 20, 2024 | Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrato... |
| CVE-2024-9036 | MEDIUM | 6.3 | 0.5% | Sep 20, 2024 | A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some u... |
| CVE-2024-9033 | MEDIUM | 5.4 | 0.4% | Sep 20, 2024 | A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. ... |
| CVE-2024-9031 | MEDIUM | 5.4 | 0.3% | Sep 20, 2024 | A vulnerability, which was classified as problematic, has been found in CodeCanyon CRMGo SaaS up to 7.2. This issue affe... |
| CVE-2024-9030 | MEDIUM | 5.4 | 0.3% | Sep 20, 2024 | A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2. This vulnerability affects unknown cod... |
| CVE-2024-47060 | MEDIUM | 6.5 | 0.4% | Sep 20, 2024 | Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associate... |
| CVE-2024-46999 | MEDIUM | 6.5 | 0.3% | Sep 20, 2024 | Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correc... |
| CVE-2024-45808 | MEDIUM | 6.5 | 0.4% | Sep 20, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that al... |
| CVE-2024-45806 | MEDIUM | 6.5 | 0.4% | Sep 20, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external cl... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now