2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41922 | HIGH | 7.5 | 8.0% | Oct 3, 2024 | A directory traversal vulnerability exists in the log files download functionality of Veertu Anka Build 1.42.0. A specia... |
| CVE-2024-41163 | HIGH | 7.5 | 47.1% | Oct 3, 2024 | A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. A specially crafted... |
| CVE-2024-39755 | HIGH | 7.8 | 0.4% | Oct 3, 2024 | A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially cr... |
| CVE-2024-36474 | HIGH | 7.8 | 0.4% | Oct 3, 2024 | An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Struc... |
| CVE-2024-25590 | HIGH | 7.5 | 0.7% | Oct 3, 2024 | An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for... |
| CVE-2024-9460 | CRITICAL | 9.8 | 0.7% | Oct 3, 2024 | A vulnerability was found in Codezips Online Shopping Portal 1.0. It has been classified as critical. Affected is an unk... |
| CVE-2024-9100 | MEDIUM | 6.5 | 0.5% | Oct 3, 2024 | Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnera... |
| CVE-2024-5803 | HIGH | 7.5 | 0.1% | Oct 3, 2024 | The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via a... |
| CVE-2024-47618 | MEDIUM | 5.4 | 0.4% | Oct 3, 2024 | Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the... |
| CVE-2024-47617 | MEDIUM | 6.1 | 0.3% | Oct 3, 2024 | Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code ... |
| CVE-2024-47614 | HIGH | 7.5 | 0.6% | Oct 3, 2024 | async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of ... |
| CVE-2024-47554 | MEDIUM | 4.3 | 1.2% | Oct 3, 2024 | Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader c... |
| CVE-2024-9313 | HIGH | 8.8 | 0.6% | Oct 3, 2024 | Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same b... |
| CVE-2024-47561 | CRITICAL | 9.2 | 3.3% | Oct 3, 2024 | Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. ... |
| CVE-2024-42504 | MEDIUM | 4.3 | 0.1% | Oct 3, 2024 | A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery... |
| CVE-2024-8159 | MEDIUM | 6.4 | 0.2% | Oct 3, 2024 | Deep Freeze 9.00.020.5760 is vulnerable to an out-of-bounds read vulnerability by triggering the 0x70014 IOCTL code of t... |
| CVE-2024-8352 | HIGH | 7.5 | 0.9% | Oct 3, 2024 | The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directory... |
| CVE-2024-47136 | HIGH | 7.8 | 0.3% | Oct 3, 2024 | Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) ... |
| CVE-2024-47135 | HIGH | 7.8 | 0.3% | Oct 3, 2024 | Stack-based buffer overflow vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming S... |
| CVE-2024-47134 | HIGH | 7.8 | 0.3% | Oct 3, 2024 | Out-of-bounds write vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software)... |
| CVE-2024-47616 | MEDIUM | 6.8 | 0.6% | Oct 2, 2024 | Pomerium is an identity and context-aware access proxy. The Pomerium databroker service is responsible for managing all ... |
| CVE-2024-45519 | CRITICAL | 9.8 | 100.0% | Oct 2, 2024 | The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,... |
| CVE-2024-28888 | HIGH | 8.8 | 1.9% | Oct 2, 2024 | A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a checkbox field object. A special... |
| CVE-2024-24117 | CRITICAL | 9.8 | 0.6% | Oct 2, 2024 | Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to g... |
| CVE-2024-8733 | HIGH | 8 | 0.2% | Oct 2, 2024 | A potential security vulnerability has been identified in the HP One Agent for certain HP PC products, which might allow... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now