2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9007 | MEDIUM | 5.4 | 0.9% | Sep 19, 2024 | A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of... |
| CVE-2024-45614 | MEDIUM | 5.4 | 0.7% | Sep 19, 2024 | Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermedi... |
| CVE-2024-9003 | MEDIUM | 5.3 | 0.3% | Sep 19, 2024 | A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects th... |
| CVE-2024-38221 | MEDIUM | 4.3 | 0.5% | Sep 19, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-25673 | MEDIUM | 6.1 | 0.3% | Sep 19, 2024 | Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection. |
| CVE-2024-47162 | MEDIUM | 5.3 | 0.3% | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page |
| CVE-2024-47160 | MEDIUM | 5.3 | 0.4% | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible |
| CVE-2024-47159 | MEDIUM | 4.3 | 0.3% | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a pro... |
| CVE-2024-8653 | MEDIUM | 6.1 | 0.3% | Sep 19, 2024 | A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific... |
| CVE-2024-8652 | MEDIUM | 6.1 | 0.3% | Sep 19, 2024 | A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific... |
| CVE-2024-8651 | MEDIUM | 5.3 | 0.4% | Sep 19, 2024 | A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whet... |
| CVE-2024-8883 | MEDIUM | 6.1 | 2.0% | Sep 19, 2024 | A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if... |
| CVE-2024-7736 | MEDIUM | 5.4 | 0.3% | Sep 19, 2024 | A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEX... |
| CVE-2024-8354 | MEDIUM | 5.5 | 0.3% | Sep 19, 2024 | A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to ... |
| CVE-2024-45770 | MEDIUM | 4.4 | 0.3% | Sep 19, 2024 | A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a ... |
| CVE-2024-45769 | MEDIUM | 5.5 | 0.3% | Sep 19, 2024 | A vulnerability was found in Performance Co-Pilot (PCP). This flaw allows an attacker to send specially crafted data to... |
| CVE-2024-47089 | MEDIUM | 6.5 | 0.2% | Sep 19, 2024 | This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID in the API ... |
| CVE-2024-47087 | MEDIUM | 6.5 | 0.4% | Sep 19, 2024 | This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID ... |
| CVE-2024-47086 | MEDIUM | 6.5 | 0.5% | Sep 19, 2024 | This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism ... |
| CVE-2024-47085 | MEDIUM | 6.5 | 0.4% | Sep 19, 2024 | This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClic... |
| CVE-2024-8850 | MEDIUM | 6.1 | 0.4% | Sep 19, 2024 | The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' ... |
| CVE-2024-8364 | MEDIUM | 5.4 | 0.3% | Sep 19, 2024 | The WP Custom Fields Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcfs-pre... |
| CVE-2024-47059 | MEDIUM | 4.3 | 0.3% | Sep 18, 2024 | When logging in with the correct username and incorrect weak password, the user receives the notification, that their pa... |
| CVE-2024-47058 | MEDIUM | 4.8 | 0.2% | Sep 18, 2024 | With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be use... |
| CVE-2024-47050 | MEDIUM | 6.1 | 0.3% | Sep 18, 2024 | Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variabl... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now