2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39753 | HIGH | 7.5 | 2.0% | Oct 22, 2024 | An modOSCE SQL Injection vulnerability in Trend Micro Apex One could allow a remote attacker to execute arbitrary code o... |
| CVE-2024-10183 | MEDIUM | 5.2 | 0.1% | Oct 22, 2024 | A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges t... |
| CVE-2024-9287 | HIGH | 7.8 | 0.6% | Oct 22, 2024 | A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual en... |
| CVE-2024-9129 | CRITICAL | 9.3 | 0.4% | Oct 22, 2024 | In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered. Reported by Dylan Ma... |
| CVE-2024-49211 | MEDIUM | 6.1 | 0.3% | Oct 22, 2024 | Reflected XSS was discovered in a Dashboard Listing Archer Platform UX page in Archer Platform 6.x before version 2024.0... |
| CVE-2024-49210 | MEDIUM | 6.1 | 0.3% | Oct 22, 2024 | Reflected XSS was discovered in an iView List Archer Platform UX page in Archer Platform 6.x before version 2024.09. A r... |
| CVE-2024-49209 | MEDIUM | 4.3 | 0.3% | Oct 22, 2024 | Archer Platform 2024.03 before version 2024.09 is affected by an API authorization bypass vulnerability related to suppo... |
| CVE-2024-49208 | LOW | 3.1 | 0.3% | Oct 22, 2024 | Archer Platform 2024.03 before version 2024.08 is affected by an authorization bypass vulnerability related to supportin... |
| CVE-2024-48708 | MEDIUM | 5.4 | 0.3% | Oct 22, 2024 | Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action ... |
| CVE-2024-48707 | MEDIUM | 5.4 | 0.3% | Oct 22, 2024 | Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit wi... |
| CVE-2024-48706 | MEDIUM | 5.4 | 0.3% | Oct 22, 2024 | Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform wi... |
| CVE-2024-48570 | HIGH | 7.5 | 0.5% | Oct 22, 2024 | Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports param... |
| CVE-2024-46538 | MEDIUM | 4.8 | 77.9% | Oct 22, 2024 | A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML v... |
| CVE-2024-45518 | HIGH | 8.8 | 20.3% | Oct 22, 2024 | An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41,... |
| CVE-2024-49373 | MEDIUM | 4.3 | 0.4% | Oct 22, 2024 | No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an a... |
| CVE-2024-48929 | MEDIUM | 4.2 | 0.2% | Oct 22, 2024 | Umbraco is a free and open source .NET content management system. In versions on the 13.x branch prior to 13.5.2 and ver... |
| CVE-2024-48927 | MEDIUM | 4.6 | 0.4% | Oct 22, 2024 | Umbraco, a free and open source .NET content management system, has a remote code execution issue in versions on the 13.... |
| CVE-2024-48926 | LOW | 3.1 | 0.2% | Oct 22, 2024 | Umbraco, a free and open source .NET content management system, has an insufficient session expiration issue in versions... |
| CVE-2024-48925 | MEDIUM | 6.5 | 0.4% | Oct 22, 2024 | Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version... |
| CVE-2024-48605 | HIGH | 7.8 | 0.5% | Oct 22, 2024 | An issue in Helakuru Desktop Application v1.1 allows a local attacker to execute arbitrary code via the lack of proper v... |
| CVE-2024-47819 | HIGH | 8.7 | 0.3% | Oct 22, 2024 | Umbraco, a free and open source .NET content management system, has a cross-site scripting vulnerability starting in ver... |
| CVE-2024-46240 | MEDIUM | 4.8 | 0.3% | Oct 22, 2024 | Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/co... |
| CVE-2024-8980 | MEDIUM | 6.1 | 0.2% | Oct 22, 2024 | The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA throug... |
| CVE-2024-43177 | CRITICAL | 9.8 | 0.3% | Oct 22, 2024 | IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute. |
| CVE-2024-43173 | LOW | 3.7 | 0.2% | Oct 22, 2024 | IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now