2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47080 | HIGH | 8.7 | 0.7% | Oct 15, 2024 | matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 t... |
| CVE-2024-9979 | MEDIUM | 5.3 | 0.2% | Oct 15, 2024 | A flaw was found in PyO3. This vulnerability causes a use-after-free issue, potentially leading to memory corruption or ... |
| CVE-2024-48948 | MEDIUM | 4.8 | 0.6% | Oct 15, 2024 | The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if t... |
| CVE-2024-9986 | CRITICAL | 9.8 | 0.8% | Oct 15, 2024 | A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue a... |
| CVE-2024-9977 | MEDIUM | 5.1 | 22.1% | Oct 15, 2024 | A vulnerability, which was classified as critical, was found in MitraStar GPT-2541GNAC BR_g5.6_1.11(WVK.0)b26. Affected ... |
| CVE-2024-48283 | CRITICAL | 9.8 | 0.6% | Oct 15, 2024 | Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-res... |
| CVE-2024-48282 | HIGH | 7.6 | 0.4% | Oct 15, 2024 | A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Manag... |
| CVE-2024-48280 | HIGH | 7.6 | 0.4% | Oct 15, 2024 | A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Managemen... |
| CVE-2024-48279 | HIGH | 7.6 | 0.6% | Oct 15, 2024 | A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Manageme... |
| CVE-2024-48278 | MEDIUM | 5.5 | 0.2% | Oct 15, 2024 | Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) v... |
| CVE-2024-9976 | CRITICAL | 9.8 | 0.5% | Oct 15, 2024 | A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an u... |
| CVE-2024-9975 | HIGH | 8.8 | 0.6% | Oct 15, 2024 | A vulnerability was found in SourceCodester Drag and Drop Image Upload 1.0. It has been rated as critical. Affected by t... |
| CVE-2024-49388 | CRITICAL | 9.1 | 0.3% | Oct 15, 2024 | Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Pro... |
| CVE-2024-49387 | HIGH | 7.5 | 0.2% | Oct 15, 2024 | Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis ... |
| CVE-2024-49384 | MEDIUM | 4.3 | 0.2% | Oct 15, 2024 | Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products ... |
| CVE-2024-49383 | MEDIUM | 4.3 | 0.2% | Oct 15, 2024 | Excessive attack surface in acep-importer service due to binding to an unrestricted IP address. The following products a... |
| CVE-2024-49382 | MEDIUM | 4.3 | 0.2% | Oct 15, 2024 | Excessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products ... |
| CVE-2024-47674 | MEDIUM | 5.5 | 0.2% | Oct 15, 2024 | In the Linux kernel, the following vulnerability has been resolved: mm: avoid leaving partial pfn mappings around in er... |
| CVE-2024-45276 | HIGH | 7.5 | 0.6% | Oct 15, 2024 | An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication. |
| CVE-2024-45275 | CRITICAL | 9.8 | 0.8% | Oct 15, 2024 | The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker ... |
| CVE-2024-45274 | CRITICAL | 9.8 | 1.5% | Oct 15, 2024 | An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication. |
| CVE-2024-45273 | HIGH | 7.8 | 0.1% | Oct 15, 2024 | An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak ... |
| CVE-2024-45272 | HIGH | 7.5 | 0.6% | Oct 15, 2024 | An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with... |
| CVE-2024-45271 | HIGH | 7.8 | 0.3% | Oct 15, 2024 | An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation. |
| CVE-2024-9974 | CRITICAL | 9.8 | 0.6% | Oct 15, 2024 | A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now