2024 CVE Vulnerabilities
39,239 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8395 | CRITICAL | 9.8 | 0.7% | Sep 5, 2024 | FlyCASS CASS and KCM systems did not correctly filter SQL queries, which made them vulnerable to attack by outside atta... |
| CVE-2024-45159 | CRITICAL | 9.8 | 0.4% | Sep 5, 2024 | An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the... |
| CVE-2024-45158 | CRITICAL | 9.8 | 0.7% | Sep 5, 2024 | An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_... |
| CVE-2024-45157 | MEDIUM | 5.1 | 0.2% | Sep 5, 2024 | An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used... |
| CVE-2024-7591 | HIGH | 7.2 | 44.1% | Sep 5, 2024 | Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMa... |
| CVE-2024-45401 | HIGH | 7.1 | 0.2% | Sep 5, 2024 | stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in ver... |
| CVE-2024-42491 | MEDIUM | 5.7 | 0.6% | Sep 5, 2024 | Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and ... |
| CVE-2024-45392 | MEDIUM | 4.3 | 0.3% | Sep 5, 2024 | SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficien... |
| CVE-2024-44728 | MEDIUM | 6.1 | 0.3% | Sep 5, 2024 | Sourcecodehero Event Management System 1.0 allows Stored Cross-Site Scripting via parameters Full Name, Address, Email, ... |
| CVE-2024-44727 | CRITICAL | 9.8 | 0.5% | Sep 5, 2024 | Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/lo... |
| CVE-2024-24759 | CRITICAL | 9.1 | 4.9% | Sep 5, 2024 | MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat ac... |
| CVE-2024-45589 | MEDIUM | 5.9 | 0.9% | Sep 5, 2024 | RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts an... |
| CVE-2024-45176 | MEDIUM | 6.1 | 0.9% | Sep 5, 2024 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper input validation, the C-MOR web ... |
| CVE-2024-45175 | HIGH | 8.8 | 0.7% | Sep 5, 2024 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It... |
| CVE-2024-45171 | HIGH | 8.8 | 0.9% | Sep 5, 2024 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is pos... |
| CVE-2024-45098 | HIGH | 8.1 | 0.4% | Sep 5, 2024 | IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource mod... |
| CVE-2024-45097 | HIGH | 7.1 | 0.3% | Sep 5, 2024 | IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user to bypass intended access restrictions and conduct resource mod... |
| CVE-2024-45096 | MEDIUM | 6.5 | 0.4% | Sep 5, 2024 | IBM Aspera Faspex 5.0.0 through 5.0.9 could allow a user with access to the package to obtain sensitive information thro... |
| CVE-2024-42885 | CRITICAL | 9.1 | 0.6% | Sep 5, 2024 | SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id param... |
| CVE-2024-8445 | MEDIUM | 5.7 | 0.4% | Sep 5, 2024 | The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain product versions, an authen... |
| CVE-2024-45178 | HIGH | 7.1 | 1.3% | Sep 5, 2024 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is pos... |
| CVE-2024-45173 | HIGH | 8.8 | 0.9% | Sep 5, 2024 | An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning ... |
| CVE-2024-44587 | HIGH | 8.8 | 0.5% | Sep 5, 2024 | itsourcecode Alton Management System 1.0 is vulnerable to SQL Injection in /noncombo_save.php via the "menu" parameter. |
| CVE-2024-8473 | MEDIUM | 6.1 | 0.3% | Sep 5, 2024 | Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of t... |
| CVE-2024-8472 | MEDIUM | 6.1 | 0.3% | Sep 5, 2024 | Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now