2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9004 | CRITICAL | 9.8 | 15.8% | Sep 19, 2024 | A vulnerability classified as critical has been found in D-Link DAR-7000 up to 20240912. Affected is an unknown function... |
| CVE-2024-9003 | MEDIUM | 5.3 | 0.3% | Sep 19, 2024 | A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects th... |
| CVE-2024-43496 | HIGH | 8.8 | 1.0% | Sep 19, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2024-43489 | HIGH | 8.8 | 0.7% | Sep 19, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2024-38221 | MEDIUM | 4.3 | 0.5% | Sep 19, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-9001 | HIGH | 8.8 | 3.9% | Sep 19, 2024 | A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the... |
| CVE-2024-40125 | CRITICAL | 9.8 | 0.9% | Sep 19, 2024 | An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allow... |
| CVE-2024-33109 | CRITICAL | 9.8 | 0.9% | Sep 19, 2024 | Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overw... |
| CVE-2024-25673 | MEDIUM | 6.1 | 0.3% | Sep 19, 2024 | Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection. |
| CVE-2024-8963 | CRITICAL | 9.1 | 98.4% | Sep 19, 2024 | Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted func... |
| CVE-2024-47162 | MEDIUM | 5.3 | 0.3% | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page |
| CVE-2024-47160 | MEDIUM | 5.3 | 0.4% | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible |
| CVE-2024-47159 | MEDIUM | 4.3 | 0.3% | Sep 19, 2024 | In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a pro... |
| CVE-2024-8653 | MEDIUM | 6.1 | 0.3% | Sep 19, 2024 | A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific... |
| CVE-2024-8652 | MEDIUM | 6.1 | 0.3% | Sep 19, 2024 | A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific... |
| CVE-2024-8651 | MEDIUM | 5.3 | 0.4% | Sep 19, 2024 | A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whet... |
| CVE-2024-38016 | HIGH | 7.8 | 0.6% | Sep 19, 2024 | Microsoft Office Visio Remote Code Execution Vulnerability |
| CVE-2024-31570 | CRITICAL | 9.8 | 0.6% | Sep 19, 2024 | libfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the PluginXPM.cpp Load function via ... |
| CVE-2024-8883 | MEDIUM | 6.1 | 2.0% | Sep 19, 2024 | A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if... |
| CVE-2024-8698 | HIGH | 7.7 | 2.0% | Sep 19, 2024 | A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly... |
| CVE-2024-8375 | HIGH | 7.8 | 0.1% | Sep 19, 2024 | There exists a use after free vulnerability in Reverb. Reverb supports the VARIANT datatype, which is supposed to repres... |
| CVE-2024-7737 | HIGH | 8.7 | 0.4% | Sep 19, 2024 | A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through ... |
| CVE-2024-7736 | MEDIUM | 5.4 | 0.3% | Sep 19, 2024 | A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEX... |
| CVE-2024-45862 | HIGH | 7.5 | 0.2% | Sep 19, 2024 | Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to ac... |
| CVE-2024-45861 | HIGH | 7.5 | 0.4% | Sep 19, 2024 | Kastle Systems firmware prior to May 1, 2024, contained a hard-coded credential, which if accessed may allow an attacker... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now