2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20659 | HIGH | 7.1 | 0.9% | Oct 8, 2024 | Windows Hyper-V Security Feature Bypass Vulnerability |
| CVE-2024-9622 | MEDIUM | 5.3 | 0.7% | Oct 8, 2024 | A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling... |
| CVE-2024-9621 | MEDIUM | 5.3 | 0.5% | Oct 8, 2024 | A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the... |
| CVE-2024-9620 | MEDIUM | 5.3 | 0.2% | Oct 8, 2024 | A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensit... |
| CVE-2024-9381 | HIGH | 7.2 | 15.7% | Oct 8, 2024 | Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass... |
| CVE-2024-9380 | HIGH | 7.2 | 63.0% | Oct 8, 2024 | An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authen... |
| CVE-2024-9379 | HIGH | 7.2 | 43.6% | Oct 8, 2024 | SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with ad... |
| CVE-2024-9167 | HIGH | 7.8 | 0.2% | Oct 8, 2024 | Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local a... |
| CVE-2024-9124 | HIGH | 7.5 | 0.5% | Oct 8, 2024 | A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 600T. If the device is overloaded with re... |
| CVE-2024-8626 | HIGH | 7.5 | 0.5% | Oct 8, 2024 | Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious... |
| CVE-2024-7612 | HIGH | 7.8 | 0.2% | Oct 8, 2024 | Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application... |
| CVE-2024-47011 | HIGH | 7.5 | 57.0% | Oct 8, 2024 | Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive infor... |
| CVE-2024-47010 | CRITICAL | 9.8 | 38.0% | Oct 8, 2024 | Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authenticatio... |
| CVE-2024-47009 | CRITICAL | 9.8 | 1.7% | Oct 8, 2024 | Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authenticatio... |
| CVE-2024-47008 | HIGH | 7.5 | 46.6% | Oct 8, 2024 | Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak se... |
| CVE-2024-47007 | HIGH | 7.5 | 1.2% | Oct 8, 2024 | A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenti... |
| CVE-2024-45918 | CRITICAL | 9.8 | 0.4% | Oct 8, 2024 | Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_g... |
| CVE-2024-44349 | CRITICAL | 9.8 | 5.6% | Oct 8, 2024 | A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute ar... |
| CVE-2024-3057 | CRITICAL | 9.8 | 0.4% | Oct 8, 2024 | A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation. |
| CVE-2024-8215 | HIGH | 8.4 | 0.4% | Oct 8, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Plat... |
| CVE-2024-47951 | MEDIUM | 5.4 | 1.4% | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings |
| CVE-2024-47950 | MEDIUM | 5.4 | 1.4% | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings |
| CVE-2024-47949 | HIGH | 7.5 | 22.9% | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location |
| CVE-2024-47948 | HIGH | 7.5 | 0.5% | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups |
| CVE-2024-47161 | MEDIUM | 6.5 | 0.3% | Oct 8, 2024 | In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now