2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38796 | MEDIUM | 5.9 | 0.4% | Sep 27, 2024 | EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an over... |
| CVE-2024-23586 | HIGH | 7.5 | 0.3% | Sep 27, 2024 | HCL Nomad is susceptible to an insufficient session expiration vulnerability. Under certain circumstances, an unauthen... |
| CVE-2024-9293 | HIGH | 8.8 | 0.5% | Sep 27, 2024 | A vulnerability classified as critical was found in skyselang yylAdmin up to 3.0. Affected by this vulnerability is the ... |
| CVE-2024-9291 | MEDIUM | 5.4 | 0.4% | Sep 27, 2024 | A vulnerability classified as problematic has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75... |
| CVE-2024-47186 | MEDIUM | 6.1 | 0.4% | Sep 27, 2024 | Filament is a collection of full-stack components for Laravel development. Versions of Filament from v3.0.0 through v3.2... |
| CVE-2024-46453 | MEDIUM | 6.1 | 0.3% | Sep 27, 2024 | A cross-site scripting (XSS) vulnerability in the component /test/ of iq3xcite v2.31 to v3.05 allows attackers to execut... |
| CVE-2024-6436 | MEDIUM | 6.5 | 0.6% | Sep 27, 2024 | An input validation vulnerability exists in the Rockwell Automation Sequence Manager™ which could allow a malicious user... |
| CVE-2024-9160 | MEDIUM | 5.4 | 0.2% | Sep 27, 2024 | In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered. |
| CVE-2024-33369 | HIGH | 8.8 | 1.1% | Sep 27, 2024 | Directory Traversal vulnerability in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary ... |
| CVE-2024-33368 | HIGH | 8.8 | 0.7% | Sep 27, 2024 | An issue in Plasmoapp RPShare Fabric mod v.1.0.0 allows a remote attacker to execute arbitrary code via the build method... |
| CVE-2024-9301 | HIGH | 7.5 | 0.7% | Sep 27, 2024 | A path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250a |
| CVE-2024-46257 | MEDIUM | 6.3 | 1.3% | Sep 27, 2024 | A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacke... |
| CVE-2024-46256 | CRITICAL | 9.8 | 3.0% | Sep 27, 2024 | A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add... |
| CVE-2024-46097 | HIGH | 8.1 | 0.4% | Sep 27, 2024 | TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is create... |
| CVE-2024-39364 | HIGH | 7 | 0.2% | Sep 27, 2024 | Advantech ADAM-5630 has built-in commands that can be executed without authenticating the user. These commands allow f... |
| CVE-2024-39275 | HIGH | 8.8 | 0.4% | Sep 27, 2024 | Cookies of authenticated Advantech ADAM-5630 users remain as active valid cookies when a session is closed. Forging req... |
| CVE-2024-38308 | MEDIUM | 6.1 | 0.3% | Sep 27, 2024 | Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the ... |
| CVE-2024-37187 | MEDIUM | 5.7 | 0.4% | Sep 27, 2024 | Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding. |
| CVE-2024-34542 | MEDIUM | 5.7 | 0.2% | Sep 27, 2024 | Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login pr... |
| CVE-2024-28948 | HIGH | 8.8 | 0.2% | Sep 27, 2024 | Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumve... |
| CVE-2024-25412 | MEDIUM | 6.1 | 0.9% | Sep 27, 2024 | A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML v... |
| CVE-2024-25411 | MEDIUM | 6.1 | 0.7% | Sep 27, 2024 | A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML v... |
| CVE-2024-9284 | HIGH | 7.1 | 0.9% | Sep 27, 2024 | A vulnerability was found in TP-LINK TL-WR841ND up to 20240920. It has been rated as critical. Affected by this issue is... |
| CVE-2024-9273 | — | — | — | Sep 27, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2024-9268 | — | — | — | Sep 27, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now