2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10313 | HIGH | 8.6 | 0.5% | Oct 24, 2024 | iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malici... |
| CVE-2024-10295 | HIGH | 7.5 | 0.4% | Oct 24, 2024 | A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly ... |
| CVE-2024-9692 | MEDIUM | 6.9 | 0.4% | Oct 24, 2024 | VIMESA VHF/FM Transmitter Blue Plus is suffering from a Denial-of-Service (DoS) vulnerability. An unauthenticated attack... |
| CVE-2024-48548 | CRITICAL | 9.3 | 0.2% | Oct 24, 2024 | The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulne... |
| CVE-2024-48547 | HIGH | 8.4 | 0.2% | Oct 24, 2024 | Incorrect access control in the firmware update and download processes of DreamCatcher Life v1.8.7 allows attackers to a... |
| CVE-2024-48546 | HIGH | 8.4 | 0.2% | Oct 24, 2024 | Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access se... |
| CVE-2024-48545 | HIGH | 8.4 | 0.2% | Oct 24, 2024 | Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access se... |
| CVE-2024-48544 | HIGH | 8.4 | 0.2% | Oct 24, 2024 | Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to... |
| CVE-2024-48542 | HIGH | 8.4 | 0.2% | Oct 24, 2024 | Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows att... |
| CVE-2024-48541 | HIGH | 8.4 | 0.2% | Oct 24, 2024 | Incorrect access control in the firmware update and download processes of Ruochan Smart v4.4.7 allows attackers to acces... |
| CVE-2024-48540 | MEDIUM | 6.2 | 0.2% | Oct 24, 2024 | Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code a... |
| CVE-2024-48539 | CRITICAL | 9.8 | 0.3% | Oct 24, 2024 | Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism. |
| CVE-2024-44206 | CRITICAL | 9.3 | 0.5% | Oct 24, 2024 | An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17.... |
| CVE-2024-44205 | MEDIUM | 5.5 | 0.2% | Oct 24, 2024 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.9 an... |
| CVE-2024-44185 | MEDIUM | 5.5 | 0.3% | Oct 24, 2024 | The issue was addressed with improved checks. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma... |
| CVE-2024-44141 | MEDIUM | 6.8 | 0.2% | Oct 24, 2024 | The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. A person with physical access to... |
| CVE-2024-40810 | MEDIUM | 5.5 | 0.2% | Oct 24, 2024 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An ... |
| CVE-2024-10336 | CRITICAL | 9.8 | 0.6% | Oct 24, 2024 | A vulnerability was found in SourceCodeHero Clothes Recommendation System 1.0. It has been rated as critical. This issue... |
| CVE-2024-10335 | CRITICAL | 9.8 | 0.7% | Oct 24, 2024 | A vulnerability was found in SourceCodester Garbage Collection Management System 1.0. It has been declared as critical. ... |
| CVE-2024-48538 | CRITICAL | 9.8 | 0.5% | Oct 24, 2024 | Incorrect access control in the firmware update and download processes of Neye3C v4.5.2.0 allows attackers to access sen... |
| CVE-2024-45031 | MEDIUM | 6.1 | 0.6% | Oct 24, 2024 | When editing objects in the Syncope Console, incomplete HTML tags could be used to bypass HTML sanitization. This made i... |
| CVE-2024-49702 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred ... |
| CVE-2024-49696 | MEDIUM | 4.8 | 0.3% | Oct 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gall... |
| CVE-2024-49695 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins WP ... |
| CVE-2024-49693 | MEDIUM | 5.4 | 0.3% | Oct 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kraft Plugins Mega... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now