2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47766 | MEDIUM | 4.9 | 0.5% | Oct 14, 2024 | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1... |
| CVE-2024-46988 | MEDIUM | 5.7 | 0.3% | Oct 14, 2024 | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1... |
| CVE-2024-46980 | MEDIUM | 4.8 | 0.3% | Oct 14, 2024 | Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1... |
| CVE-2024-46528 | MEDIUM | 4.3 | 1.6% | Oct 14, 2024 | An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSp... |
| CVE-2024-48799 | HIGH | 7.5 | 0.5% | Oct 14, 2024 | An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information... |
| CVE-2024-48798 | HIGH | 7.5 | 0.5% | Oct 14, 2024 | An issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive inform... |
| CVE-2024-48797 | HIGH | 7.5 | 0.5% | Oct 14, 2024 | An issue in PCS Engineering Preston Cinema (com.prestoncinema.app) 0.2.0 allows a remote attacker to obtain sensitive in... |
| CVE-2024-48796 | HIGH | 7.5 | 0.5% | Oct 14, 2024 | An issue in EQUES com.eques.plug 1.0.1 allows a remote attacker to obtain sensitive information via the firmware update ... |
| CVE-2024-48168 | CRITICAL | 9.8 | 0.9% | Oct 14, 2024 | A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing a... |
| CVE-2024-46535 | CRITICAL | 9.8 | 0.4% | Oct 14, 2024 | Jepaas v7.2.8 was discovered to contain a SQL injection vulnerability via the orderSQL parameter at /homePortal/loadUser... |
| CVE-2024-45741 | MEDIUM | 5.4 | 12.9% | Oct 14, 2024 | In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.2... |
| CVE-2024-45740 | MEDIUM | 5.4 | 0.4% | Oct 14, 2024 | In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403, a low-privileged ... |
| CVE-2024-45739 | MEDIUM | 4.9 | 0.5% | Oct 14, 2024 | In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for lo... |
| CVE-2024-45738 | MEDIUM | 4.9 | 0.5% | Oct 14, 2024 | In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters ... |
| CVE-2024-45737 | LOW | 3.5 | 0.2% | Oct 14, 2024 | In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and 9... |
| CVE-2024-45736 | MEDIUM | 6.5 | 0.5% | Oct 14, 2024 | In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2... |
| CVE-2024-45735 | MEDIUM | 4.3 | 0.3% | Oct 14, 2024 | In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform version... |
| CVE-2024-45734 | MEDIUM | 4.3 | 0.3% | Oct 14, 2024 | In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" S... |
| CVE-2024-45733 | HIGH | 8.8 | 1.1% | Oct 14, 2024 | In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or... |
| CVE-2024-45732 | MEDIUM | 6.5 | 0.4% | Oct 14, 2024 | In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.... |
| CVE-2024-45731 | HIGH | 8 | 0.5% | Oct 14, 2024 | In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "a... |
| CVE-2024-8184 | MEDIUM | 6.5 | 1.0% | Oct 14, 2024 | There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized u... |
| CVE-2024-6763 | MEDIUM | 5.3 | 1.0% | Oct 14, 2024 | Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class,... |
| CVE-2024-6762 | MEDIUM | 6.5 | 0.9% | Oct 14, 2024 | Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the s... |
| CVE-2024-48153 | CRITICAL | 9.8 | 0.7% | Oct 14, 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now