2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9570 | HIGH | 8.8 | 3.0% | Oct 7, 2024 | A vulnerability was found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this issue is the function ... |
| CVE-2024-46446 | CRITICAL | 9.8 | 1.4% | Oct 7, 2024 | Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identi... |
| CVE-2024-46278 | HIGH | 8.4 | 2.6% | Oct 7, 2024 | Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console. |
| CVE-2024-46041 | HIGH | 8.8 | 0.3% | Oct 7, 2024 | IoT Haat Smart Plug IH-IN-16A-S v5.16.1 is vulnerable to Authentication Bypass by Capture-replay. |
| CVE-2024-46040 | MEDIUM | 6.5 | 0.3% | Oct 7, 2024 | IoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S v5.16.1 suffers from Insufficient Session Expiration. The lack of validation... |
| CVE-2024-45932 | MEDIUM | 4.8 | 0.4% | Oct 7, 2024 | Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organiz... |
| CVE-2024-28710 | MEDIUM | 6.1 | 0.5% | Oct 7, 2024 | Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code ... |
| CVE-2024-28709 | MEDIUM | 6.1 | 0.5% | Oct 7, 2024 | Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code... |
| CVE-2024-9576 | HIGH | 7.8 | 0.1% | Oct 7, 2024 | Vulnerability in Distro Linux Workbooth v2.5 that allows to escalate privileges to the root user by manipulating the net... |
| CVE-2024-9574 | MEDIUM | 6.5 | 0.5% | Oct 7, 2024 | SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could a... |
| CVE-2024-9573 | MEDIUM | 6.5 | 0.3% | Oct 7, 2024 | SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which cou... |
| CVE-2024-9572 | MEDIUM | 5.4 | 0.3% | Oct 7, 2024 | Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplan... |
| CVE-2024-9571 | MEDIUM | 5.4 | 0.3% | Oct 7, 2024 | Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplan... |
| CVE-2024-9569 | HIGH | 8.8 | 1.3% | Oct 7, 2024 | A vulnerability has been found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this vulnerability is ... |
| CVE-2024-9568 | HIGH | 8.8 | 1.3% | Oct 7, 2024 | A vulnerability, which was classified as critical, was found in D-Link DIR-619L B1 2.06. Affected is the function formAd... |
| CVE-2024-45933 | MEDIUM | 6.6 | 0.2% | Oct 7, 2024 | OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the... |
| CVE-2024-9567 | HIGH | 8.8 | 1.3% | Oct 7, 2024 | A vulnerability, which was classified as critical, has been found in D-Link DIR-619L B1 2.06. This issue affects the fun... |
| CVE-2024-9566 | HIGH | 8.8 | 1.8% | Oct 7, 2024 | A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. This vulnerability affects the function for... |
| CVE-2024-46325 | MEDIUM | 5.5 | 0.2% | Oct 7, 2024 | TP-Link WR740N V6 has a stack overflow vulnerability via the ssid parameter in /userRpm/popupSiteSurveyRpm.htm url. |
| CVE-2024-45153 | MEDIUM | 5.4 | 0.4% | Oct 7, 2024 | Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-43047 | HIGH | 7.8 | 0.7% | Oct 7, 2024 | Memory corruption while maintaining memory maps of HLOS memory. |
| CVE-2024-42027 | MEDIUM | 6.7 | 0.5% | Oct 7, 2024 | The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to ... |
| CVE-2024-38425 | MEDIUM | 6.1 | 0.1% | Oct 7, 2024 | Information disclosure while sending implicit broadcast containing APP launch information. |
| CVE-2024-38399 | HIGH | 7.8 | 0.1% | Oct 7, 2024 | Memory corruption while processing user packets to generate page faults. |
| CVE-2024-38397 | HIGH | 7.5 | 0.3% | Oct 7, 2024 | Transient DOS while parsing probe response and assoc response frame. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now