2024 CVE Vulnerabilities
39,239 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4629 | MEDIUM | 6.5 | 0.8% | Sep 3, 2024 | A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the tim... |
| CVE-2024-45678 | MEDIUM | 4.2 | 0.3% | Sep 3, 2024 | Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECD... |
| CVE-2024-45391 | HIGH | 7.5 | 0.3% | Sep 3, 2024 | Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prio... |
| CVE-2024-45390 | CRITICAL | 9.8 | 0.4% | Sep 3, 2024 | @blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within... |
| CVE-2024-45389 | MEDIUM | 5.4 | 0.4% | Sep 3, 2024 | Pagefind, a fully static search library, initializes its dynamic JavaScript and WebAssembly files relative to the locati... |
| CVE-2024-45180 | MEDIUM | 5.4 | 0.2% | Sep 3, 2024 | SquaredUp DS for SCOM 6.2.1.11104 allows XSS. |
| CVE-2024-41434 | MEDIUM | 4.3 | 0.4% | Sep 3, 2024 | PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal. This allows atta... |
| CVE-2024-45310 | LOW | 3.6 | 0.3% | Sep 3, 2024 | runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as w... |
| CVE-2024-45307 | CRITICAL | 9.8 | 0.3% | Sep 3, 2024 | SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in version... |
| CVE-2024-43803 | MEDIUM | 4.9 | 0.6% | Sep 3, 2024 | The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. The `BareMetalHost` (... |
| CVE-2024-43413 | MEDIUM | 4.8 | 0.3% | Sep 3, 2024 | Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cr... |
| CVE-2024-41436 | HIGH | 7.5 | 0.6% | Sep 3, 2024 | ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl. |
| CVE-2024-41435 | HIGH | 7.5 | 0.5% | Sep 3, 2024 | YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter. |
| CVE-2024-7619 | — | — | — | Sep 3, 2024 | Rejected reason: Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdra... |
| CVE-2024-42904 | MEDIUM | 6.1 | 0.3% | Sep 3, 2024 | A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML vi... |
| CVE-2024-42903 | MEDIUM | 6.5 | 0.5% | Sep 3, 2024 | A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806 and before allows atta... |
| CVE-2024-42902 | HIGH | 8.8 | 1.0% | Sep 3, 2024 | An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via ... |
| CVE-2024-42901 | MEDIUM | 4.8 | 0.4% | Sep 3, 2024 | A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted ... |
| CVE-2024-38456 | HIGH | 7.8 | 0.2% | Sep 3, 2024 | HIGH-LEIT V05.08.01.03 and HIGH-LEIT V04.25.00.00 to 4.25.01.01 for Windows from Vivavis contain an insecure file and fo... |
| CVE-2024-43412 | MEDIUM | 5.4 | 0.3% | Sep 3, 2024 | Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cr... |
| CVE-2024-6119 | HIGH | 7.5 | 66.6% | Sep 3, 2024 | Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may atte... |
| CVE-2024-42991 | HIGH | 8.1 | 0.8% | Sep 3, 2024 | MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution. |
| CVE-2024-7654 | MEDIUM | 6.1 | 0.3% | Sep 3, 2024 | An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-dis... |
| CVE-2024-7346 | MEDIUM | 4.8 | 0.2% | Sep 3, 2024 | Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perfo... |
| CVE-2024-7345 | CRITICAL | 9.6 | 0.6% | Sep 3, 2024 | Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injectio... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now