2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10086 | MEDIUM | 6.1 | 0.4% | Oct 30, 2024 | A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Co... |
| CVE-2024-10006 | MEDIUM | 5.8 | 0.5% | Oct 30, 2024 | A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentio... |
| CVE-2024-10005 | MEDIUM | 5.8 | 0.7% | Oct 30, 2024 | A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intent... |
| CVE-2024-51427 | CRITICAL | 9.8 | 0.6% | Oct 30, 2024 | An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an... |
| CVE-2024-51426 | HIGH | 8.8 | 0.5% | Oct 30, 2024 | An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an... |
| CVE-2024-51425 | HIGH | 8.8 | 0.4% | Oct 30, 2024 | An issue in the WaterToken smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have ... |
| CVE-2024-51424 | CRITICAL | 9.8 | 0.6% | Oct 30, 2024 | An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an... |
| CVE-2024-51419 | MEDIUM | 6.1 | 0.3% | Oct 30, 2024 | Cross Site Scripting vulnerability in Shenzhen Interconnection Harbor Network Technology Co., Ltd Ofweek Online Exhibiti... |
| CVE-2024-51243 | HIGH | 7.2 | 0.9% | Oct 30, 2024 | The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deploy... |
| CVE-2024-51242 | MEDIUM | 6.5 | 0.4% | Oct 30, 2024 | A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployControl... |
| CVE-2024-48807 | MEDIUM | 5.4 | 0.3% | Oct 30, 2024 | Cross Site Scripting vulnerability in PHPGurukul Doctor Appointment Management System v.1.0 allows a local attacker to e... |
| CVE-2024-48735 | HIGH | 7.7 | 1.0% | Oct 30, 2024 | Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote ... |
| CVE-2024-48734 | HIGH | 8.8 | 0.6% | Oct 30, 2024 | Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote atta... |
| CVE-2024-48733 | HIGH | 8.8 | 0.7% | Oct 30, 2024 | SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to e... |
| CVE-2024-48346 | MEDIUM | 6.1 | 0.2% | Oct 30, 2024 | xtreme1 <= v0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /api/data/upload path. The vulnerab... |
| CVE-2024-48112 | CRITICAL | 9.8 | 0.9% | Oct 30, 2024 | A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to ... |
| CVE-2024-48093 | HIGH | 8 | 0.6% | Oct 30, 2024 | Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Exe... |
| CVE-2024-43382 | MEDIUM | 5.9 | 0.2% | Oct 30, 2024 | Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being u... |
| CVE-2024-48272 | MEDIUM | 6.5 | 0.6% | Oct 30, 2024 | D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers t... |
| CVE-2024-48271 | HIGH | 8.8 | 0.9% | Oct 30, 2024 | D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly ... |
| CVE-2024-10546 | MEDIUM | 6.3 | 0.3% | Oct 30, 2024 | A vulnerability classified as critical was found in open-scratch Teaching 在线教学平台 up to 2.7. This vulnerability affects u... |
| CVE-2024-48202 | CRITICAL | 9.8 | 0.6% | Oct 30, 2024 | icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile. |
| CVE-2024-46531 | MEDIUM | 6.3 | 0.3% | Oct 30, 2024 | phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchi... |
| CVE-2024-9419 | CRITICAL | 9.8 | 0.7% | Oct 30, 2024 | Client / Server PCs with the HP Smart Universal Printing Driver installed are potentially vulnerable to Remote Code Exec... |
| CVE-2024-48648 | MEDIUM | 6.1 | 0.3% | Oct 30, 2024 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attacker... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now