2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45607 | MEDIUM | 5.3 | 14.1% | Sep 12, 2024 | whatsapp-api-js is a TypeScript server agnostic Whatsapp's Official API framework. It's possible to check the payload va... |
| CVE-2024-8311 | MEDIUM | 6.5 | 0.5% | Sep 12, 2024 | An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, ... |
| CVE-2024-4472 | MEDIUM | 5.5 | 0.2% | Sep 12, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 17.1.7, starting from 17.2 pr... |
| CVE-2024-45383 | MEDIUM | 5 | 1.5% | Sep 12, 2024 | A mishandling of IRP requests vulnerability exists in the HDAudBus_DMA interface of Microsoft High Definition Audio Bus ... |
| CVE-2024-45303 | MEDIUM | 6.1 | 0.2% | Sep 12, 2024 | Discourse Calendar plugin adds the ability to create a dynamic calendar in the first post of a topic to Discourse. Rende... |
| CVE-2024-45182 | MEDIUM | 5.5 | 0.2% | Sep 12, 2024 | An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70 An improper bounds che... |
| CVE-2024-34336 | MEDIUM | 5.3 | 0.4% | Sep 12, 2024 | User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists i... |
| CVE-2024-34335 | MEDIUM | 6.1 | 0.3% | Sep 12, 2024 | ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability ... |
| CVE-2024-25270 | MEDIUM | 4.3 | 0.4% | Sep 12, 2024 | An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulner... |
| CVE-2024-41629 | MEDIUM | 5.5 | 0.2% | Sep 12, 2024 | An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive informa... |
| CVE-2024-8635 | MEDIUM | 6.5 | 0.6% | Sep 12, 2024 | A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to ... |
| CVE-2024-6840 | MEDIUM | 6.6 | 0.4% | Sep 12, 2024 | An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S A... |
| CVE-2024-6389 | MEDIUM | 4.3 | 0.4% | Sep 12, 2024 | An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and... |
| CVE-2024-5435 | MEDIUM | 6.5 | 0.4% | Sep 12, 2024 | An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all ve... |
| CVE-2024-4612 | MEDIUM | 6.1 | 0.4% | Sep 12, 2024 | An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, a... |
| CVE-2024-6702 | MEDIUM | 4.8 | 0.2% | Sep 12, 2024 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage. |
| CVE-2024-6701 | MEDIUM | 4.8 | 0.2% | Sep 12, 2024 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type. |
| CVE-2024-6700 | MEDIUM | 4.8 | 0.2% | Sep 12, 2024 | Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name. |
| CVE-2024-6658 | MEDIUM | 6.8 | 0.6% | Sep 12, 2024 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This is... |
| CVE-2024-42484 | MEDIUM | 6.5 | 0.4% | Sep 12, 2024 | ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An Out-of-Bound (OOB) vulnerability was discov... |
| CVE-2024-42483 | MEDIUM | 6.5 | 0.3% | Sep 12, 2024 | ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An replay attacks vulnerability was discovered... |
| CVE-2024-45856 | MEDIUM | 5.4 | 0.5% | Sep 12, 2024 | A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a J... |
| CVE-2024-8750 | MEDIUM | 6.1 | 0.2% | Sep 12, 2024 | Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve sess... |
| CVE-2024-8622 | MEDIUM | 6.1 | 0.4% | Sep 12, 2024 | The amCharts: Charts and Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'amcharts_jav... |
| CVE-2024-2010 | MEDIUM | 6.1 | 0.2% | Sep 12, 2024 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in TE Informatics V5 allows ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now