2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-46802 | MEDIUM | 5.5 | 0.2% | Sep 27, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: added NULL check at start of dc_va... |
| CVE-2024-46441 | HIGH | 8.8 | 0.6% | Sep 27, 2024 | An arbitrary file upload vulnerability in YPay 1.2.0 allows attackers to execute arbitrary code via a ZIP archive to the... |
| CVE-2024-9280 | CRITICAL | 9.8 | 0.5% | Sep 27, 2024 | A vulnerability has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff and classified as c... |
| CVE-2024-9279 | MEDIUM | 4.8 | 0.4% | Sep 27, 2024 | A vulnerability, which was classified as problematic, was found in funnyzpc Mee-Admin up to 1.6. This affects an unknown... |
| CVE-2024-8644 | HIGH | 7.5 | 0.3% | Sep 27, 2024 | Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipul... |
| CVE-2024-8643 | CRITICAL | 9.8 | 0.4% | Sep 27, 2024 | Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking. This issue affects Va... |
| CVE-2024-8609 | HIGH | 7.5 | 0.5% | Sep 27, 2024 | Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System for Infor... |
| CVE-2024-8608 | MEDIUM | 5.4 | 0.3% | Sep 27, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Oceanic Sof... |
| CVE-2024-8607 | CRITICAL | 9.8 | 0.5% | Sep 27, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic Software V... |
| CVE-2024-9278 | MEDIUM | 5.1 | 0.4% | Sep 27, 2024 | A vulnerability, which was classified as critical, has been found in HuankeMao SCRM up to 0.0.3. Affected by this issue ... |
| CVE-2024-9277 | MEDIUM | 6.5 | 0.9% | Sep 27, 2024 | A vulnerability classified as problematic was found in Langflow up to 1.0.18. Affected by this vulnerability is an unkno... |
| CVE-2024-9276 | MEDIUM | 5.3 | 0.3% | Sep 27, 2024 | A vulnerability classified as problematic has been found in TMsoft MyAuth Gateway 3. Affected is an unknown function of ... |
| CVE-2024-9275 | MEDIUM | 6.3 | 0.4% | Sep 27, 2024 | A vulnerability was found in jeanmarc77 123solar up to 1.8.4.5. It has been rated as critical. This issue affects some u... |
| CVE-2024-9136 | HIGH | 7.5 | 0.2% | Sep 27, 2024 | Access permission verification vulnerability in the App Multiplier module Impact: Successful exploitation of this vulner... |
| CVE-2024-47294 | HIGH | 7.5 | 0.2% | Sep 27, 2024 | Access permission verification vulnerability in the input method framework module Impact: Successful exploitation of thi... |
| CVE-2024-47293 | HIGH | 7.5 | 0.2% | Sep 27, 2024 | Out-of-bounds write vulnerability in the HAL-WIFI module Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2024-47292 | MEDIUM | 5.5 | 0.1% | Sep 27, 2024 | Path traversal vulnerability in the Bluetooth module Impact: Successful exploitation of this vulnerability may affect se... |
| CVE-2024-47291 | MEDIUM | 5.5 | 0.1% | Sep 27, 2024 | Permission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerabilit... |
| CVE-2024-47290 | MEDIUM | 5.5 | 0.1% | Sep 27, 2024 | Input validation vulnerability in the USB service module Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2024-9202 | MEDIUM | 5.3 | 0.4% | Sep 27, 2024 | In Eclipse Dataspace Components versions 0.1.3 to 0.9.0, the Connector component filters which datasets (= data offers) ... |
| CVE-2024-6931 | MEDIUM | 6.1 | 16.8% | Sep 27, 2024 | The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all ver... |
| CVE-2024-6654 | MEDIUM | 6.8 | 0.2% | Sep 27, 2024 | Products for macOS enables a user logged on to the system to perform a denial-of-service attack, which could be misused ... |
| CVE-2024-41930 | MEDIUM | 6.1 | 0.2% | Sep 27, 2024 | Cross-site scripting vulnerability exists in MF Teacher Performance Management System version 6. If this vulnerability i... |
| CVE-2024-38861 | HIGH | 7.4 | 0.2% | Sep 27, 2024 | Improper Certificate Validation in Checkmk Exchange plugin MikroTik allows attackers in MitM position to intercept traff... |
| CVE-2024-39435 | HIGH | 7.8 | 0.1% | Sep 27, 2024 | In Logmanager service, there is a possible missing verification incorrect input. This could lead to local escalation of ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now