2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45798 | CRITICAL | 9.9 | 0.8% | Sep 17, 2024 | arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Th... |
| CVE-2024-45612 | MEDIUM | 5.3 | 0.3% | Sep 17, 2024 | Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, whic... |
| CVE-2024-45537 | MEDIUM | 6.5 | 0.6% | Sep 17, 2024 | Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionali... |
| CVE-2024-45384 | MEDIUM | 5.3 | 0.8% | Sep 17, 2024 | Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j ... |
| CVE-2024-43460 | HIGH | 8.8 | 0.7% | Sep 17, 2024 | Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacke... |
| CVE-2024-38183 | CRITICAL | 9.8 | 0.8% | Sep 17, 2024 | An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a ne... |
| CVE-2024-8945 | HIGH | 8.8 | 14.5% | Sep 17, 2024 | A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulner... |
| CVE-2024-8944 | CRITICAL | 9.8 | 1.1% | Sep 17, 2024 | A vulnerability, which was classified as critical, was found in code-projects Hospital Management System 1.0. This affec... |
| CVE-2024-8796 | MEDIUM | 5.3 | 0.6% | Sep 17, 2024 | Under the default configuration, Devise-Two-Factor versions >= 2.2.0 & < 6.0.0 generate TOTP shared secrets that are 120... |
| CVE-2024-45804 | — | — | — | Sep 17, 2024 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2024-45682 | CRITICAL | 9.8 | 2.0% | Sep 17, 2024 | There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operatin... |
| CVE-2024-42503 | HIGH | 7.2 | 1.5% | Sep 17, 2024 | Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitatio... |
| CVE-2024-42502 | HIGH | 7.2 | 1.8% | Sep 17, 2024 | Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of t... |
| CVE-2024-42501 | HIGH | 7.2 | 1.2% | Sep 17, 2024 | An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability all... |
| CVE-2024-38813 | CRITICAL | 9.8 | 16.7% | Sep 17, 2024 | The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Serve... |
| CVE-2024-38812 | CRITICAL | 9.8 | 54.1% | Sep 17, 2024 | The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious acto... |
| CVE-2024-38380 | MEDIUM | 5.4 | 0.4% | Sep 17, 2024 | This vulnerability occurs when user-supplied input is improperly sanitized and then reflected back to the user's browser... |
| CVE-2024-8939 | MEDIUM | 6.2 | 0.2% | Sep 17, 2024 | A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the vll... |
| CVE-2024-8768 | HIGH | 7.5 | 0.7% | Sep 17, 2024 | A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, res... |
| CVE-2024-7788 | HIGH | 7.8 | 0.2% | Sep 17, 2024 | Improper Digital Signature Invalidation vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows ... |
| CVE-2024-47049 | HIGH | 8.2 | 0.6% | Sep 17, 2024 | The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URL... |
| CVE-2024-47047 | HIGH | 7.5 | 0.5% | Sep 17, 2024 | An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of ... |
| CVE-2024-38860 | MEDIUM | 6.1 | 0.3% | Sep 17, 2024 | Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious li... |
| CVE-2024-22303 | HIGH | 8.8 | 0.4% | Sep 17, 2024 | Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez:... |
| CVE-2024-21743 | HIGH | 8.8 | 0.4% | Sep 17, 2024 | Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez L... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now