2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47887 | MEDIUM | 6.6 | 1.0% | Oct 16, 2024 | Action Pack is a framework for handling and responding to web requests. Starting in version 4.0.0 and prior to versions ... |
| CVE-2024-47836 | MEDIUM | 4.3 | 0.5% | Oct 16, 2024 | Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability all... |
| CVE-2024-47522 | HIGH | 7.5 | 0.6% | Oct 16, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-47188 | HIGH | 7.5 | 0.3% | Oct 16, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-47187 | HIGH | 7.5 | 0.3% | Oct 16, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-45797 | HIGH | 7.5 | 0.7% | Oct 16, 2024 | LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Prior to version 0.5.49, unboun... |
| CVE-2024-45796 | MEDIUM | 5.3 | 0.5% | Oct 16, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-45795 | HIGH | 7.5 | 0.5% | Oct 16, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-41128 | MEDIUM | 6.6 | 1.1% | Oct 16, 2024 | Action Pack is a framework for handling and responding to web requests. Starting in version 3.1.0 and prior to versions ... |
| CVE-2024-9143 | MEDIUM | 4.3 | 6.0% | Oct 16, 2024 | Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial ... |
| CVE-2024-4692 | LOW | 2.4 | 0.3% | Oct 16, 2024 | Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allow... |
| CVE-2024-4690 | HIGH | 8 | 0.4% | Oct 16, 2024 | Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD ... |
| CVE-2024-4211 | LOW | 2.4 | 0.3% | Oct 16, 2024 | Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allow... |
| CVE-2024-4189 | HIGH | 8 | 0.4% | Oct 16, 2024 | Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD ... |
| CVE-2024-4184 | HIGH | 8 | 0.4% | Oct 16, 2024 | Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD ... |
| CVE-2024-46606 | MEDIUM | 5.4 | 0.4% | Oct 16, 2024 | A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to ... |
| CVE-2024-46605 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to ... |
| CVE-2024-45072 | MEDIUM | 5.5 | 0.4% | Oct 16, 2024 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when process... |
| CVE-2024-45071 | MEDIUM | 4.8 | 0.2% | Oct 16, 2024 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a p... |
| CVE-2024-38814 | HIGH | 8.8 | 14.6% | Oct 16, 2024 | An authenticated SQL injection vulnerability in VMware HCX was privately reported to VMware. A malicious authenticated ... |
| CVE-2024-20512 | MEDIUM | 6.1 | 0.3% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) c... |
| CVE-2024-20463 | HIGH | 7.1 | 0.3% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al... |
| CVE-2024-20462 | MEDIUM | 5.5 | 0.2% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter fir... |
| CVE-2024-20461 | MEDIUM | 6 | 0.2% | Oct 16, 2024 | A vulnerability in the CLI of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, ... |
| CVE-2024-20460 | MEDIUM | 6.1 | 0.3% | Oct 16, 2024 | A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could al... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now