2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43364 | HIGH | 8.2 | 34.4% | Oct 7, 2024 | Cacti is an open source performance and fault management framework. The `title` parameter is not properly sanitized when... |
| CVE-2024-43363 | HIGH | 7.2 | 35.8% | Oct 7, 2024 | Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious h... |
| CVE-2024-43362 | MEDIUM | 5.4 | 35.5% | Oct 7, 2024 | Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized wh... |
| CVE-2024-47976 | MEDIUM | 6.7 | 0.2% | Oct 7, 2024 | Improper access removal handling in firmware of some Solidigm DC Products may allow an attacker with physical access to ... |
| CVE-2024-47972 | MEDIUM | 4 | 0.2% | Oct 7, 2024 | Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially control the p... |
| CVE-2024-47971 | MEDIUM | 6.5 | 0.1% | Oct 7, 2024 | Improper error handling in firmware of some SSD DC Products may allow an attacker to enable denial of service. |
| CVE-2024-47079 | MEDIUM | 6.4 | 0.2% | Oct 7, 2024 | Meshtastic is an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Mesht... |
| CVE-2024-45293 | HIGH | 7.5 | 2.9% | Oct 7, 2024 | PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for pre... |
| CVE-2024-45292 | MEDIUM | 5.4 | 0.3% | Oct 7, 2024 | PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. `\PhpOffice\PhpSpreadsheet\Writer\Html` ... |
| CVE-2024-31449 | HIGH | 8.8 | 4.5% | Oct 7, 2024 | Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua... |
| CVE-2024-31228 | MEDIUM | 6.5 | 1.0% | Oct 7, 2024 | Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service b... |
| CVE-2024-31227 | MEDIUM | 4.4 | 0.4% | Oct 7, 2024 | Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may creat... |
| CVE-2024-47975 | HIGH | 7 | 0.2% | Oct 7, 2024 | Improper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access t... |
| CVE-2024-47559 | HIGH | 8.8 | 0.5% | Oct 7, 2024 | Authenticated RCE via Path Traversal |
| CVE-2024-47558 | HIGH | 8.8 | 0.5% | Oct 7, 2024 | Authenticated RCE via Path Traversal |
| CVE-2024-47557 | CRITICAL | 9.8 | 0.5% | Oct 7, 2024 | Pre-Auth RCE via Path Traversal |
| CVE-2024-47556 | CRITICAL | 9.8 | 0.5% | Oct 7, 2024 | Pre-Auth RCE via Path Traversal |
| CVE-2024-45894 | MEDIUM | 4.9 | 0.3% | Oct 7, 2024 | BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request. |
| CVE-2024-44068 | HIGH | 8.1 | 1.0% | Oct 7, 2024 | An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 9... |
| CVE-2024-47555 | HIGH | 8.3 | 0.2% | Oct 7, 2024 | Missing Authentication - User & System Configuration |
| CVE-2024-46076 | CRITICAL | 9.8 | 0.5% | Oct 7, 2024 | RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabl... |
| CVE-2024-44674 | MEDIUM | 5.7 | 3.9% | Oct 7, 2024 | D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained thr... |
| CVE-2024-42831 | MEDIUM | 6.1 | 1.1% | Oct 7, 2024 | A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to ex... |
| CVE-2024-46300 | MEDIUM | 6.1 | 0.4% | Oct 7, 2024 | itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in regi... |
| CVE-2024-27458 | HIGH | 8.8 | 0.2% | Oct 7, 2024 | A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escala... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now