2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-46373 | HIGH | 8.8 | 0.5% | Sep 18, 2024 | Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend. |
| CVE-2024-46372 | MEDIUM | 6.1 | 0.3% | Sep 18, 2024 | DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement manageme... |
| CVE-2024-40568 | CRITICAL | 9.8 | 0.7% | Sep 18, 2024 | Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote a... |
| CVE-2024-44589 | HIGH | 8.8 | 0.9% | Sep 18, 2024 | Stack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows atta... |
| CVE-2024-43025 | MEDIUM | 6.1 | 0.3% | Sep 18, 2024 | An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and... |
| CVE-2024-43024 | MEDIUM | 6.1 | 0.3% | Sep 18, 2024 | Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to... |
| CVE-2024-39339 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota c... |
| CVE-2024-8287 | HIGH | 7.5 | 0.2% | Sep 18, 2024 | Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the... |
| CVE-2024-34057 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing re... |
| CVE-2024-46989 | MEDIUM | 5.3 | 0.3% | Sep 18, 2024 | spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for custom... |
| CVE-2024-46987 | HIGH | 7.7 | 14.6% | Sep 18, 2024 | Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. A path traversal vulnerability ... |
| CVE-2024-46986 | CRITICAL | 9.9 | 35.5% | Sep 18, 2024 | Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnera... |
| CVE-2024-46979 | MEDIUM | 5.3 | 0.5% | Sep 18, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible t... |
| CVE-2024-46978 | MEDIUM | 6.5 | 0.5% | Sep 18, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible f... |
| CVE-2024-46959 | MEDIUM | 6.5 | 0.2% | Sep 18, 2024 | runofast Indoor Security Camera for Baby Monitor has a default password of password for the root account. This allows ac... |
| CVE-2024-45601 | HIGH | 7.5 | 0.3% | Sep 18, 2024 | Mesop is a Python-based UI framework designed for rapid web apps development. A vulnerability has been discovered and fi... |
| CVE-2024-45523 | CRITICAL | 9.1 | 0.4% | Sep 18, 2024 | An issue was discovered in Bravura Security Fabric versions 12.3.x before 12.3.5.32784, 12.4.x before 12.4.3.35110, 12.5... |
| CVE-2024-34399 | CRITICAL | 9.8 | 0.5% | Sep 18, 2024 | **UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker ... |
| CVE-2024-46990 | MEDIUM | 5 | 0.5% | Sep 18, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to loca... |
| CVE-2024-45813 | MEDIUM | 5.3 | 0.7% | Sep 18, 2024 | find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route ... |
| CVE-2024-45298 | MEDIUM | 4.3 | 0.4% | Sep 18, 2024 | Wiki.js is an open source wiki app built on Node.js. A disabled user can still gain access to a wiki by abusing the pass... |
| CVE-2024-46086 | HIGH | 8.8 | 0.3% | Sep 18, 2024 | FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_mana... |
| CVE-2024-6878 | CRITICAL | 9.2 | 0.4% | Sep 18, 2024 | Files or Directories Accessible to External Parties vulnerability in Eliz Software Panel allows Collect Data from Common... |
| CVE-2024-6877 | MEDIUM | 6.1 | 0.3% | Sep 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Softwa... |
| CVE-2024-5960 | CRITICAL | 9.8 | 0.4% | Sep 18, 2024 | Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials. This iss... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now