2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49399 | HIGH | 8.7 | 0.4% | Oct 17, 2024 | The affected product is vulnerable to an attacker being able to use commands without providing a password which may allo... |
| CVE-2024-49398 | HIGH | 8.8 | 0.5% | Oct 17, 2024 | The affected product is vulnerable to unrestricted file uploads, which may allow an attacker to remotely execute code. |
| CVE-2024-49397 | CRITICAL | 9.2 | 0.4% | Oct 17, 2024 | The affected product is vulnerable to a cross-site scripting attack which may allow an attacker to bypass authentication... |
| CVE-2024-49396 | HIGH | 8.7 | 0.4% | Oct 17, 2024 | The affected product is vulnerable due to insufficiently protected credentials, which may allow an attacker to impersona... |
| CVE-2024-48192 | HIGH | 8 | 0.4% | Oct 17, 2024 | Tenda G3 v15.01.0.5(2848_755)_EN was discovered to contain a hardcoded password vulnerability in /etc_ro/shadow, which a... |
| CVE-2024-10073 | HIGH | 7.5 | 0.5% | Oct 17, 2024 | A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function Clusteri... |
| CVE-2024-10072 | HIGH | 8.8 | 0.5% | Oct 17, 2024 | A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. This issue affects the function act... |
| CVE-2024-9414 | HIGH | 7 | 0.6% | Oct 17, 2024 | In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code... |
| CVE-2024-10071 | HIGH | 8.8 | 0.5% | Oct 17, 2024 | A vulnerability classified as critical was found in ESAFENET CDG 5. This vulnerability affects the function actionUpdate... |
| CVE-2024-9683 | MEDIUM | 5.3 | 0.3% | Oct 17, 2024 | A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is prov... |
| CVE-2024-48920 | CRITICAL | 9.1 | 0.5% | Oct 17, 2024 | PutongOJ is online judging software. Prior to version 2.1.0-beta.1, unprivileged users can escalate privileges by constr... |
| CVE-2024-47459 | MEDIUM | 5.5 | 0.2% | Oct 17, 2024 | Substance3D - Sampler versions 4.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead ... |
| CVE-2024-10070 | HIGH | 8.8 | 0.5% | Oct 17, 2024 | A vulnerability classified as critical has been found in ESAFENET CDG 5. This affects the function actionPolicyPush of t... |
| CVE-2024-10069 | HIGH | 8.8 | 0.5% | Oct 17, 2024 | A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function actio... |
| CVE-2024-6333 | HIGH | 7.2 | 1.2% | Oct 17, 2024 | Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products. |
| CVE-2024-49315 | HIGH | 8.6 | 0.6% | Oct 17, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CodeFlock FREE DOWNLOAD ... |
| CVE-2024-49580 | MEDIUM | 5.3 | 0.3% | Oct 17, 2024 | In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure |
| CVE-2024-49579 | MEDIUM | 6.1 | 0.4% | Oct 17, 2024 | In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized... |
| CVE-2024-48048 | HIGH | 7.1 | 0.2% | Oct 17, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in GabbyKhrmon Wsify Widget wsify-widget allows Stored XSS.This issue af... |
| CVE-2024-48046 | MEDIUM | 5.9 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Contact ... |
| CVE-2024-48037 | MEDIUM | 5.4 | 0.2% | Oct 17, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget new-contact-form-widget allows Cross Si... |
| CVE-2024-48036 | MEDIUM | 5.4 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT B... |
| CVE-2024-48032 | HIGH | 7.1 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sumitsurai Feature... |
| CVE-2024-48031 | MEDIUM | 6.5 | 0.2% | Oct 17, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in sumitsurai Featured Posts with Multiple Custom Groups (FPMCG) feature... |
| CVE-2024-48025 | MEDIUM | 6.5 | 0.2% | Oct 17, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dogrow Simple Base... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now