2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9033 | MEDIUM | 5.4 | 0.4% | Sep 20, 2024 | A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. ... |
| CVE-2024-9032 | HIGH | 8.8 | 0.7% | Sep 20, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0. Affec... |
| CVE-2024-9031 | MEDIUM | 5.4 | 0.3% | Sep 20, 2024 | A vulnerability, which was classified as problematic, has been found in CodeCanyon CRMGo SaaS up to 7.2. This issue affe... |
| CVE-2024-9030 | MEDIUM | 5.4 | 0.3% | Sep 20, 2024 | A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2. This vulnerability affects unknown cod... |
| CVE-2024-9043 | CRITICAL | 9.8 | 1.4% | Sep 20, 2024 | Secure Email Gateway from Cellopoint has Buffer Overflow Vulnerability in authentication process. Remote unauthenticated... |
| CVE-2024-8853 | CRITICAL | 9.8 | 0.6% | Sep 20, 2024 | The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to ... |
| CVE-2024-41721 | HIGH | 8.1 | 0.8% | Sep 20, 2024 | An insufficient boundary validation in the USB code could lead to an out-of-bounds read on the heap, which could potenti... |
| CVE-2024-9011 | CRITICAL | 9.8 | 0.6% | Sep 20, 2024 | A vulnerability, which was classified as critical, was found in code-projects Crud Operation System 1.0. Affected is an ... |
| CVE-2024-9009 | CRITICAL | 9.8 | 0.6% | Sep 20, 2024 | A vulnerability, which was classified as critical, has been found in code-projects Online Quiz Site 1.0. This issue affe... |
| CVE-2024-47060 | MEDIUM | 6.5 | 0.4% | Sep 20, 2024 | Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associate... |
| CVE-2024-47000 | HIGH | 7.5 | 0.4% | Sep 20, 2024 | Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work corre... |
| CVE-2024-46999 | MEDIUM | 6.5 | 0.3% | Sep 20, 2024 | Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correc... |
| CVE-2024-45810 | HIGH | 7.5 | 0.6% | Sep 20, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy will crash when the http async client is handl... |
| CVE-2024-45809 | HIGH | 7.5 | 0.4% | Sep 20, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. Jwt filter will lead to an Envoy crash when clear ro... |
| CVE-2024-45808 | MEDIUM | 6.5 | 0.4% | Sep 20, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that al... |
| CVE-2024-45807 | HIGH | 7.5 | 0.5% | Sep 20, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2... |
| CVE-2024-45806 | MEDIUM | 6.5 | 0.4% | Sep 20, 2024 | Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external cl... |
| CVE-2024-9008 | CRITICAL | 9.8 | 0.6% | Sep 19, 2024 | A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. This vulnerability affec... |
| CVE-2024-9007 | MEDIUM | 5.4 | 0.9% | Sep 19, 2024 | A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of... |
| CVE-2024-9006 | HIGH | 8.8 | 0.7% | Sep 19, 2024 | A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some ... |
| CVE-2024-7207 | — | — | — | Sep 19, 2024 | Rejected reason: Duplicate of CVE-2024-45806. |
| CVE-2024-46984 | CRITICAL | 9.8 | 0.6% | Sep 19, 2024 | The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and interoperabil... |
| CVE-2024-46983 | CRITICAL | 9.8 | 0.7% | Sep 19, 2024 | sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses... |
| CVE-2024-45614 | MEDIUM | 5.4 | 0.7% | Sep 19, 2024 | Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermedi... |
| CVE-2024-45410 | HIGH | 7.5 | 1.5% | Sep 19, 2024 | Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers s... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now