2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-46869 | MEDIUM | 5.5 | 0.2% | Sep 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: Allocate memory for driver... |
| CVE-2024-46510 | HIGH | 7.6 | 0.3% | Sep 30, 2024 | ESAFENET CDG v5 was discovered to contain a SQL injection vulnerability via the id parameter in the NavigationAjax inter... |
| CVE-2024-46475 | MEDIUM | 4.8 | 0.3% | Sep 30, 2024 | A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows at... |
| CVE-2024-47172 | MEDIUM | 5.4 | 0.3% | Sep 30, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacke... |
| CVE-2024-47064 | MEDIUM | 6.1 | 0.3% | Sep 30, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an atta... |
| CVE-2024-47063 | MEDIUM | 6.1 | 0.3% | Sep 30, 2024 | Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If a malic... |
| CVE-2024-46313 | HIGH | 8 | 2.2% | Sep 30, 2024 | TP-Link WR941ND V6 has a stack overflow vulnerability in the ssid parameter in /userRpm/popupSiteSurveyRpm.htm. |
| CVE-2024-46293 | CRITICAL | 9.8 | 0.4% | Sep 30, 2024 | Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authori... |
| CVE-2024-46280 | HIGH | 8.8 | 0.3% | Sep 30, 2024 | PIX-LINK LV-WR22 RE3002-P1-01_V117.0 is vulnerable to Improper Access Control. The TELNET service is enabled with weak c... |
| CVE-2024-45792 | MEDIUM | 6.5 | 0.5% | Sep 30, 2024 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered... |
| CVE-2024-6051 | MEDIUM | 4.3 | 0.2% | Sep 30, 2024 | Cross Application Scripting vulnerability in Vercom S.A. Redlink SDK in specific situations allows local code injection ... |
| CVE-2024-47641 | MEDIUM | 6.5 | 0.2% | Sep 30, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Muhammad Shakeel C... |
| CVE-2024-45920 | MEDIUM | 5.4 | 0.3% | Sep 30, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability in Solvait 24.4.2 allows remote attackers to inject malicious scripts ... |
| CVE-2024-45772 | HIGH | 8 | 0.6% | Sep 30, 2024 | Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replica... |
| CVE-2024-9329 | MEDIUM | 6.1 | 0.7% | Sep 30, 2024 | In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the ... |
| CVE-2024-8459 | MEDIUM | 4.9 | 0.3% | Sep 30, 2024 | Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, ... |
| CVE-2024-8458 | HIGH | 8.8 | 0.3% | Sep 30, 2024 | Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CS... |
| CVE-2024-8457 | MEDIUM | 4.8 | 0.3% | Sep 30, 2024 | Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters,... |
| CVE-2024-8456 | CRITICAL | 9.8 | 0.6% | Sep 30, 2024 | Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, a... |
| CVE-2024-8455 | MEDIUM | 5.9 | 0.3% | Sep 30, 2024 | The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authe... |
| CVE-2024-8454 | HIGH | 7.5 | 0.6% | Sep 30, 2024 | The swctrl service is used to detect and remotely manage PLANET Technology devices. Certain switch models have a Denial-... |
| CVE-2024-8453 | MEDIUM | 4.9 | 0.3% | Sep 30, 2024 | Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salte... |
| CVE-2024-6394 | HIGH | 7.5 | 0.6% | Sep 30, 2024 | A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to un... |
| CVE-2024-45200 | MEDIUM | 6.3 | 1.4% | Sep 30, 2024 | In Nintendo Mario Kart 8 Deluxe before 3.0.3, the LAN/LDN local multiplayer implementation allows a remote attacker to e... |
| CVE-2024-42496 | LOW | 2.4 | 0.2% | Sep 30, 2024 | Smart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now