2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9171 | — | — | — | Sep 27, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2024-8630 | CRITICAL | 9.8 | 0.6% | Sep 27, 2024 | Alisonic Sibylla devices are vulnerable to SQL injection attacks, which could allow complete access to the database. |
| CVE-2024-8310 | CRITICAL | 9.8 | 0.7% | Sep 27, 2024 | OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full... |
| CVE-2024-6981 | CRITICAL | 9.8 | 0.6% | Sep 27, 2024 | OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without pro... |
| CVE-2024-46367 | CRITICAL | 9.6 | 0.5% | Sep 27, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary... |
| CVE-2024-46366 | HIGH | 8.8 | 0.5% | Sep 27, 2024 | A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbi... |
| CVE-2024-38809 | MEDIUM | 5.3 | 0.9% | Sep 27, 2024 | Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of... |
| CVE-2024-22170 | CRITICAL | 9.2 | 0.5% | Sep 27, 2024 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-s... |
| CVE-2024-6983 | HIGH | 8.8 | 1.3% | Sep 27, 2024 | mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backe... |
| CVE-2024-47077 | MEDIUM | 6.5 | 0.4% | Sep 27, 2024 | authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one appl... |
| CVE-2024-47070 | CRITICAL | 9 | 0.5% | Sep 27, 2024 | authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 al... |
| CVE-2024-45745 | MEDIUM | 4.3 | 0.3% | Sep 27, 2024 | TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute Jav... |
| CVE-2024-45744 | MEDIUM | 4.3 | 0.2% | Sep 27, 2024 | TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can r... |
| CVE-2024-46472 | HIGH | 8.6 | 0.4% | Sep 27, 2024 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page. |
| CVE-2024-46471 | HIGH | 7.5 | 0.5% | Sep 27, 2024 | The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and conten... |
| CVE-2024-46470 | MEDIUM | 6.1 | 0.3% | Sep 27, 2024 | Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaS... |
| CVE-2024-46333 | MEDIUM | 4.8 | 0.3% | Sep 27, 2024 | An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web sc... |
| CVE-2024-46331 | HIGH | 7.2 | 0.6% | Sep 27, 2024 | ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. T... |
| CVE-2024-44912 | HIGH | 7.5 | 0.5% | Sep 27, 2024 | NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TM subsystem (crypto_tm.c). |
| CVE-2024-44911 | HIGH | 7.5 | 0.5% | Sep 27, 2024 | NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TC subsystem (crypto_tc.c). |
| CVE-2024-44910 | HIGH | 7.5 | 0.5% | Sep 27, 2024 | NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (crypto_aos.c). |
| CVE-2024-40510 | HIGH | 8.2 | 0.7% | Sep 27, 2024 | Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t... |
| CVE-2024-40509 | HIGH | 7.3 | 0.8% | Sep 27, 2024 | Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via t... |
| CVE-2024-3373 | CRITICAL | 9.2 | 0.4% | Sep 27, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RSM Design Website... |
| CVE-2024-9283 | MEDIUM | 4.8 | 0.3% | Sep 27, 2024 | A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown functi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now