2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7318 | MEDIUM | 4.8 | 0.4% | Sep 9, 2024 | A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period i... |
| CVE-2024-7260 | MEDIUM | 6.1 | 0.5% | Sep 9, 2024 | An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and ... |
| CVE-2024-45411 | HIGH | 8.6 | 0.8% | Sep 9, 2024 | Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user... |
| CVE-2024-45296 | HIGH | 7.5 | 0.9% | Sep 9, 2024 | path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular exp... |
| CVE-2024-42759 | MEDIUM | 6.3 | 0.4% | Sep 9, 2024 | An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente... |
| CVE-2024-24510 | MEDIUM | 6.1 | 0.5% | Sep 9, 2024 | Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via t... |
| CVE-2024-44849 | CRITICAL | 9.8 | 46.3% | Sep 9, 2024 | Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php. |
| CVE-2024-44335 | HIGH | 8.8 | 12.4% | Sep 9, 2024 | D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.... |
| CVE-2024-44334 | HIGH | 8.8 | 31.8% | Sep 9, 2024 | D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.... |
| CVE-2024-45406 | MEDIUM | 4.8 | 0.3% | Sep 9, 2024 | Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fie... |
| CVE-2024-44333 | HIGH | 8.8 | 12.4% | Sep 9, 2024 | D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.... |
| CVE-2024-8605 | MEDIUM | 5.4 | 0.5% | Sep 9, 2024 | A vulnerability classified as problematic was found in code-projects Inventory Management 1.0. This vulnerability affect... |
| CVE-2024-8604 | MEDIUM | 6.1 | 0.5% | Sep 9, 2024 | A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects... |
| CVE-2024-44721 | CRITICAL | 9.8 | 0.6% | Sep 9, 2024 | SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php. |
| CVE-2024-44720 | HIGH | 7.5 | 0.7% | Sep 9, 2024 | SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php. |
| CVE-2024-8373 | MEDIUM | 4.3 | 0.6% | Sep 9, 2024 | Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to ... |
| CVE-2024-8372 | MEDIUM | 4.3 | 0.6% | Sep 9, 2024 | Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source... |
| CVE-2024-8042 | LOW | 3.1 | 0.2% | Sep 9, 2024 | Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues wher... |
| CVE-2024-45041 | HIGH | 8.8 | 0.6% | Sep 9, 2024 | External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secr... |
| CVE-2024-40643 | CRITICAL | 9.6 | 0.7% | Sep 9, 2024 | Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by ... |
| CVE-2024-7015 | CRITICAL | 9.8 | 0.4% | Sep 9, 2024 | Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authent... |
| CVE-2024-44375 | HIGH | 7.5 | 0.7% | Sep 9, 2024 | D-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function. |
| CVE-2024-8601 | MEDIUM | 6.5 | 0.5% | Sep 9, 2024 | This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on c... |
| CVE-2024-6572 | HIGH | 7.4 | 0.3% | Sep 9, 2024 | Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk... |
| CVE-2024-37288 | HIGH | 8.8 | 1.0% | Sep 9, 2024 | A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document con... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now