2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45597 | MEDIUM | 5.3 | 0.3% | Sep 10, 2024 | Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. Scripts passing user-controlled values to ht... |
| CVE-2024-8441 | MEDIUM | 6.7 | 0.4% | Sep 10, 2024 | An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local auth... |
| CVE-2024-8320 | MEDIUM | 5.3 | 1.2% | Sep 10, 2024 | Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote ... |
| CVE-2024-8655 | MEDIUM | 6.9 | 0.5% | Sep 10, 2024 | A vulnerability was found in Mercury MNVR816 up to 2.0.1.0.5. It has been classified as problematic. This affects an unk... |
| CVE-2024-45596 | MEDIUM | 6.5 | 0.6% | Sep 10, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access cred... |
| CVE-2024-34831 | MEDIUM | 6.1 | 0.9% | Sep 10, 2024 | cross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the im... |
| CVE-2024-44872 | MEDIUM | 6.1 | 0.4% | Sep 10, 2024 | A reflected cross-site scripting (XSS) vulnerability in moziloCMS v3.0 allows attackers to execute arbitrary code in the... |
| CVE-2024-43487 | MEDIUM | 6.5 | 1.2% | Sep 10, 2024 | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2024-43482 | MEDIUM | 6.5 | 1.1% | Sep 10, 2024 | Microsoft Outlook for iOS Information Disclosure Vulnerability |
| CVE-2024-43476 | MEDIUM | 5.4 | 0.8% | Sep 10, 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2024-38256 | MEDIUM | 5.5 | 0.7% | Sep 10, 2024 | Windows Kernel-Mode Driver Information Disclosure Vulnerability |
| CVE-2024-38254 | MEDIUM | 6.2 | 0.7% | Sep 10, 2024 | Windows Authentication Information Disclosure Vulnerability |
| CVE-2024-38235 | MEDIUM | 6.5 | 0.7% | Sep 10, 2024 | Windows Hyper-V Denial of Service Vulnerability |
| CVE-2024-38234 | MEDIUM | 6.5 | 0.9% | Sep 10, 2024 | Windows Networking Denial of Service Vulnerability |
| CVE-2024-38217 | MEDIUM | 5.4 | 9.8% | Sep 10, 2024 | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2024-37342 | MEDIUM | 4.3 | 1.7% | Sep 10, 2024 | Microsoft SQL Server Native Scoring Information Disclosure Vulnerability |
| CVE-2024-37337 | MEDIUM | 4.3 | 1.7% | Sep 10, 2024 | Microsoft SQL Server Native Scoring Information Disclosure Vulnerability |
| CVE-2024-6876 | MEDIUM | 4.4 | 0.2% | Sep 10, 2024 | Out-of-Bounds read vulnerability in OSCAT Basic Library allows an local, unprivileged attacker to access limited interna... |
| CVE-2024-45592 | MEDIUM | 6.1 | 0.4% | Sep 10, 2024 | auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Pri... |
| CVE-2024-45591 | MEDIUM | 5.3 | 3.4% | Sep 10, 2024 | XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker k... |
| CVE-2024-45407 | MEDIUM | 5.3 | 0.3% | Sep 10, 2024 | Sunshine is a self-hosted game stream host for Moonlight. Clients that experience a MITM attack during the pairing proce... |
| CVE-2024-44815 | MEDIUM | 4.6 | 0.6% | Sep 10, 2024 | Vulnerability in Hathway Skyworth Router CM5100 v.4.1.1.24 allows a physically proximate attacker to obtain user credent... |
| CVE-2024-44676 | MEDIUM | 4.8 | 0.5% | Sep 10, 2024 | eladmin v2.7 and before is vulnerable to Cross Site Scripting (XSS) which allows an attacker to execute arbitrary code v... |
| CVE-2024-45393 | MEDIUM | 6.4 | 0.2% | Sep 10, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacke... |
| CVE-2024-43800 | MEDIUM | 4.7 | 0.6% | Sep 10, 2024 | serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() ma... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now