2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48150 | CRITICAL | 9.8 | 0.7% | Oct 14, 2024 | D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function. |
| CVE-2024-41997 | MEDIUM | 6.6 | 1.2% | Oct 14, 2024 | An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulne... |
| CVE-2024-9823 | HIGH | 7.5 | 0.9% | Oct 14, 2024 | There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote ... |
| CVE-2024-48261 | — | — | — | Oct 14, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-48251. Reason: This candidate is a reservation d... |
| CVE-2024-48259 | HIGH | 7.3 | 0.9% | Oct 14, 2024 | Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign. |
| CVE-2024-48257 | CRITICAL | 9.8 | 0.6% | Oct 14, 2024 | Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin. |
| CVE-2024-48251 | CRITICAL | 9.8 | 0.5% | Oct 14, 2024 | Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode. |
| CVE-2024-48249 | HIGH | 7.3 | 0.4% | Oct 14, 2024 | Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode. |
| CVE-2024-40616 | — | — | — | Oct 14, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-9936 | MEDIUM | 6.5 | 0.3% | Oct 14, 2024 | When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially lea... |
| CVE-2024-8602 | MEDIUM | 6.3 | 0.4% | Oct 14, 2024 | When the XML is read from the codes in the PDF and parsed using a DocumentBuilder, the default settings of the DocumentB... |
| CVE-2024-7847 | HIGH | 7.8 | 0.2% | Oct 14, 2024 | VULNERABILITY DETAILS Rockwell Automation used the latest versions of the CVSS scoring system to assess the following v... |
| CVE-2024-48255 | CRITICAL | 9.8 | 0.4% | Oct 14, 2024 | Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection. |
| CVE-2024-48253 | CRITICAL | 9.8 | 0.4% | Oct 14, 2024 | Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection. |
| CVE-2024-48120 | MEDIUM | 5.4 | 0.6% | Oct 14, 2024 | X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject ma... |
| CVE-2024-48119 | MEDIUM | 5.4 | 0.3% | Oct 14, 2024 | Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary H... |
| CVE-2024-9139 | HIGH | 8.6 | 1.4% | Oct 14, 2024 | The affected product permits OS command injection through improperly restricted commands, potentially allowing attackers... |
| CVE-2024-9137 | CRITICAL | 9.4 | 0.5% | Oct 14, 2024 | The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulner... |
| CVE-2024-46911 | MEDIUM | 4.7 | 0.4% | Oct 14, 2024 | Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websi... |
| CVE-2024-43701 | HIGH | 7.8 | 0.1% | Oct 14, 2024 | Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory... |
| CVE-2024-38863 | HIGH | 7.5 | 0.4% | Oct 14, 2024 | Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35... |
| CVE-2024-38862 | MEDIUM | 4.4 | 0.3% | Oct 14, 2024 | Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35, <2.1.0p48 and ... |
| CVE-2024-9924 | CRITICAL | 9.8 | 0.8% | Oct 14, 2024 | The fix for CVE-2024-26261 was incomplete, and and the specific package for OAKlouds from Hgiga remains at risk. Unauthe... |
| CVE-2024-9923 | MEDIUM | 4.9 | 0.6% | Oct 14, 2024 | The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with ... |
| CVE-2024-49214 | MEDIUM | 5.3 | 0.5% | Oct 14, 2024 | QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now