2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47840 | MEDIUM | 4.8 | 0.3% | Oct 5, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2024-47848 | MEDIUM | 6.9 | 0.5% | Oct 5, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - PageTri... |
| CVE-2024-47913 | MEDIUM | 5.3 | 0.4% | Oct 4, 2024 | An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1... |
| CVE-2024-47911 | HIGH | 7.2 | 0.4% | Oct 4, 2024 | In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-membe... |
| CVE-2024-47910 | HIGH | 7.2 | 0.5% | Oct 4, 2024 | An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Admini... |
| CVE-2024-37869 | HIGH | 8.8 | 1.0% | Oct 4, 2024 | File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbi... |
| CVE-2024-37868 | HIGH | 8.8 | 1.0% | Oct 4, 2024 | File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbi... |
| CVE-2024-9054 | HIGH | 8.8 | 14.6% | Oct 4, 2024 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Inform... |
| CVE-2024-7801 | MEDIUM | 6.5 | 0.8% | Oct 4, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProv... |
| CVE-2024-47764 | MEDIUM | 6.9 | 0.7% | Oct 4, 2024 | cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields ... |
| CVE-2024-43687 | MEDIUM | 6.1 | 0.8% | Oct 4, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip T... |
| CVE-2024-43686 | MEDIUM | 6.1 | 11.2% | Oct 4, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip T... |
| CVE-2024-43685 | CRITICAL | 9.8 | 0.4% | Oct 4, 2024 | Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue... |
| CVE-2024-43684 | HIGH | 8.8 | 0.2% | Oct 4, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-... |
| CVE-2024-43683 | MEDIUM | 6.1 | 0.2% | Oct 4, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP... |
| CVE-2024-46078 | HIGH | 7.5 | 0.3% | Oct 4, 2024 | itsourcecode Sports Management System Project 1.0 is vulnerable to SQL Injection in the function delete_category of the ... |
| CVE-2024-46077 | MEDIUM | 5.4 | 0.3% | Oct 4, 2024 | itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted p... |
| CVE-2024-8149 | MEDIUM | 4.6 | 0.4% | Oct 4, 2024 | There is a reflected Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.1 and 11.2 that may ... |
| CVE-2024-8148 | MEDIUM | 6.1 | 0.3% | Oct 4, 2024 | There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthe... |
| CVE-2024-47211 | MEDIUM | 5.3 | 0.7% | Oct 4, 2024 | In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26... |
| CVE-2024-44439 | MEDIUM | 5.9 | 0.2% | Oct 4, 2024 | An issue in Shanghai Zhouma Network Technology CO., Ltd IMS Intelligent Manufacturing Collaborative Internet of Things S... |
| CVE-2024-41516 | MEDIUM | 5.4 | 0.4% | Oct 4, 2024 | A Reflected cross-site scripting (XSS) vulnerability in "ccHandler.aspx" CADClick <= 1.11.0 allows remote attackers to i... |
| CVE-2024-41515 | MEDIUM | 5.4 | 0.4% | Oct 4, 2024 | A reflected cross-site scripting (XSS) vulnerability in "ccHandlerResource.ashx" in CADClick <= 1.11.0 allows remote att... |
| CVE-2024-41514 | MEDIUM | 5.4 | 0.4% | Oct 4, 2024 | A reflected cross-site scripting (XSS) vulnerability in "PrevPgGroup.aspx" in CADClick v1.11.0 and before allows remote ... |
| CVE-2024-41513 | MEDIUM | 5.4 | 0.4% | Oct 4, 2024 | A reflected cross-site scripting (XSS) vulnerability in "Artikel.aspx" in CADClick v1.11.0 and before allows remote atta... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now