2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-47766MEDIUM4.9Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1...
CVE-2024-46988MEDIUM5.7Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1...
CVE-2024-46980MEDIUM4.8Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1...
CVE-2024-46528MEDIUM4.3An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSp...
CVE-2024-48799HIGH7.5An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information...
CVE-2024-48798HIGH7.5An issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive inform...
CVE-2024-48797HIGH7.5An issue in PCS Engineering Preston Cinema (com.prestoncinema.app) 0.2.0 allows a remote attacker to obtain sensitive in...
CVE-2024-48796HIGH7.5An issue in EQUES com.eques.plug 1.0.1 allows a remote attacker to obtain sensitive information via the firmware update ...
CVE-2024-48168CRITICAL9.8A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing a...
CVE-2024-46535CRITICAL9.8Jepaas v7.2.8 was discovered to contain a SQL injection vulnerability via the orderSQL parameter at /homePortal/loadUser...
CVE-2024-45741MEDIUM5.4In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.2...
CVE-2024-45740MEDIUM5.4In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403, a low-privileged ...
CVE-2024-45739MEDIUM4.9In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for lo...
CVE-2024-45738MEDIUM4.9In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters ...
CVE-2024-45737LOW3.5In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and 9...
CVE-2024-45736MEDIUM6.5In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2...
CVE-2024-45735MEDIUM4.3In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform version...
CVE-2024-45734MEDIUM4.3In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" S...
CVE-2024-45733HIGH8.8In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or...
CVE-2024-45732MEDIUM6.5In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2....
CVE-2024-45731HIGH8In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "a...
CVE-2024-8184MEDIUM6.5There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized u...
CVE-2024-6763MEDIUM5.3Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class,...
CVE-2024-6762MEDIUM6.5Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the s...
CVE-2024-48153CRITICAL9.8DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now