2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37779 | HIGH | 8.8 | 1.1% | Sep 23, 2024 | WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via t... |
| CVE-2024-39843 | MEDIUM | 6.7 | 2.1% | Sep 23, 2024 | A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL comm... |
| CVE-2024-39842 | HIGH | 7.2 | 1.7% | Sep 23, 2024 | A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL comm... |
| CVE-2024-39342 | MEDIUM | 6.6 | 0.1% | Sep 23, 2024 | Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier use... |
| CVE-2024-39341 | MEDIUM | 5.9 | 0.2% | Sep 23, 2024 | Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and... |
| CVE-2024-0005 | HIGH | 8.8 | 0.6% | Sep 23, 2024 | A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotel... |
| CVE-2024-0004 | HIGH | 7.2 | 0.6% | Sep 23, 2024 | A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to... |
| CVE-2024-0003 | HIGH | 7.2 | 0.5% | Sep 23, 2024 | A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an ... |
| CVE-2024-0002 | CRITICAL | 9.8 | 0.5% | Sep 23, 2024 | A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to th... |
| CVE-2024-0001 | CRITICAL | 9.8 | 0.9% | Sep 23, 2024 | A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active ... |
| CVE-2024-9014 | MEDIUM | 6.5 | 9.7% | Sep 23, 2024 | pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows ... |
| CVE-2024-40442 | HIGH | 7.2 | 1.0% | Sep 23, 2024 | An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pi... |
| CVE-2024-40441 | MEDIUM | 6.6 | 0.6% | Sep 23, 2024 | An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pi... |
| CVE-2024-47069 | MEDIUM | 6.1 | 0.4% | Sep 23, 2024 | Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy set... |
| CVE-2024-47068 | MEDIUM | 6.1 | 0.7% | Sep 23, 2024 | Rollup is a module bundler for JavaScript. Versions prior to 2.79.2, 3.29.5, and 4.22.4 are susceptible to a DOM Clobber... |
| CVE-2024-47066 | HIGH | 8.8 | 10.8% | Sep 23, 2024 | Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forger... |
| CVE-2024-46997 | CRITICAL | 9.8 | 1.5% | Sep 23, 2024 | DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote com... |
| CVE-2024-46985 | HIGH | 7.5 | 0.7% | Sep 23, 2024 | DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity in... |
| CVE-2024-41228 | HIGH | 7.6 | 0.3% | Sep 23, 2024 | A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to es... |
| CVE-2024-34331 | CRITICAL | 9.8 | 1.0% | Sep 23, 2024 | A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privil... |
| CVE-2024-23972 | MEDIUM | 6.8 | 0.8% | Sep 23, 2024 | Sony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution Vulnerability. This vulnerability all... |
| CVE-2024-23934 | HIGH | 8.8 | 1.0% | Sep 23, 2024 | Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2024-23933 | MEDIUM | 6.8 | 0.7% | Sep 23, 2024 | Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows p... |
| CVE-2024-23922 | MEDIUM | 6.8 | 1.7% | Sep 23, 2024 | Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows p... |
| CVE-2024-46241 | MEDIUM | 5.9 | 0.2% | Sep 23, 2024 | PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now