2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7671 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, may force an Out-of-Bounds Writ... |
| CVE-2024-7670 | HIGH | 7.8 | 0.2% | Sep 30, 2024 | A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force an Out-of-Bounds Read. ... |
| CVE-2024-46503 | — | — | — | Sep 30, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-28808 | LOW | 2.7 | 0.4% | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenti... |
| CVE-2024-28807 | MEDIUM | 6.5 | 0.1% | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @C... |
| CVE-2024-28813 | HIGH | 8.4 | 0.2% | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management applicatio... |
| CVE-2024-28812 | HIGH | 8.8 | 0.3% | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) w... |
| CVE-2024-28811 | LOW | 3.3 | 0.3% | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute a... |
| CVE-2024-28810 | MEDIUM | 6.6 | 0.2% | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT... |
| CVE-2024-46635 | MEDIUM | 5.9 | 0.3% | Sep 30, 2024 | An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access se... |
| CVE-2024-46511 | HIGH | 7.5 | 0.2% | Sep 30, 2024 | LoadZilla LLC LoadLogic v1.4.3 was discovered to contain insecure permissions vulnerability which allows a remote attack... |
| CVE-2024-42017 | CRITICAL | 10 | 0.5% | Sep 30, 2024 | An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In t... |
| CVE-2024-35495 | MEDIUM | 4.3 | 0.2% | Sep 30, 2024 | An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Bu... |
| CVE-2024-28809 | HIGH | 8.8 | 0.2% | Sep 30, 2024 | An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update package... |
| CVE-2024-9158 | MEDIUM | 4.6 | 0.3% | Sep 30, 2024 | A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local at... |
| CVE-2024-47536 | MEDIUM | 5.4 | 0.4% | Sep 30, 2024 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo rig... |
| CVE-2024-46549 | HIGH | 7.6 | 0.3% | Sep 30, 2024 | An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connecti... |
| CVE-2024-46548 | MEDIUM | 6.3 | 0.1% | Sep 30, 2024 | TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eave... |
| CVE-2024-46540 | MEDIUM | 6.3 | 0.7% | Sep 30, 2024 | A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attacke... |
| CVE-2024-45993 | MEDIUM | 6.5 | 0.5% | Sep 30, 2024 | Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb. |
| CVE-2024-47532 | MEDIUM | 6.5 | 0.7% | Sep 30, 2024 | RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to prote... |
| CVE-2024-47531 | LOW | 3.5 | 0.3% | Sep 30, 2024 | Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass in... |
| CVE-2024-47530 | MEDIUM | 6.1 | 0.4% | Sep 30, 2024 | Scout is a web-based visualizer for VCF-files. Open redirect vulnerability allows performing phishing attacks on users b... |
| CVE-2024-47178 | MEDIUM | 5.3 | 0.5% | Sep 30, 2024 | basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe... |
| CVE-2024-47067 | MEDIUM | 6.1 | 0.4% | Sep 30, 2024 | AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerabil... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now