2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34399 | CRITICAL | 9.8 | 0.5% | Sep 18, 2024 | **UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker ... |
| CVE-2024-6878 | CRITICAL | 9.2 | 0.4% | Sep 18, 2024 | Files or Directories Accessible to External Parties vulnerability in Eliz Software Panel allows Collect Data from Common... |
| CVE-2024-5960 | CRITICAL | 9.8 | 0.4% | Sep 18, 2024 | Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials. This iss... |
| CVE-2024-44542 | CRITICAL | 9.8 | 1.1% | Sep 18, 2024 | SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.... |
| CVE-2024-35515 | CRITICAL | 9.8 | 0.9% | Sep 18, 2024 | Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code. |
| CVE-2024-34026 | CRITICAL | 9.8 | 2.4% | Sep 18, 2024 | A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v... |
| CVE-2024-8892 | CRITICAL | 9.1 | 0.3% | Sep 18, 2024 | Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value... |
| CVE-2024-8889 | CRITICAL | 9.1 | 0.4% | Sep 18, 2024 | Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value... |
| CVE-2024-44004 | CRITICAL | 9.8 | 0.5% | Sep 17, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo... |
| CVE-2024-43978 | CRITICAL | 9.8 | 0.5% | Sep 17, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super S... |
| CVE-2024-43976 | CRITICAL | 9.8 | 0.5% | Sep 17, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super S... |
| CVE-2024-8956 | CRITICAL | 9.1 | 60.9% | Sep 17, 2024 | PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does... |
| CVE-2024-45798 | CRITICAL | 9.9 | 0.8% | Sep 17, 2024 | arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Th... |
| CVE-2024-38183 | CRITICAL | 9.8 | 0.8% | Sep 17, 2024 | An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a ne... |
| CVE-2024-8944 | CRITICAL | 9.8 | 1.1% | Sep 17, 2024 | A vulnerability, which was classified as critical, was found in code-projects Hospital Management System 1.0. This affec... |
| CVE-2024-45682 | CRITICAL | 9.8 | 2.0% | Sep 17, 2024 | There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operatin... |
| CVE-2024-38813 | CRITICAL | 9.8 | 16.7% | Sep 17, 2024 | The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Serve... |
| CVE-2024-38812 | CRITICAL | 9.8 | 54.1% | Sep 17, 2024 | The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious acto... |
| CVE-2024-7873 | CRITICAL | 9.4 | 0.4% | Sep 17, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escapi... |
| CVE-2024-8767 | CRITICAL | 9.9 | 0.5% | Sep 17, 2024 | Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected... |
| CVE-2024-7387 | CRITICAL | 9.1 | 2.3% | Sep 17, 2024 | A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious... |
| CVE-2024-45496 | CRITICAL | 9.9 | 0.9% | Sep 17, 2024 | A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Pla... |
| CVE-2024-44148 | CRITICAL | 10 | 0.7% | Sep 17, 2024 | This issue was addressed with improved validation of file attributes. This issue is fixed in macOS Sequoia 15. An app ma... |
| CVE-2024-44146 | CRITICAL | 10 | 0.7% | Sep 17, 2024 | A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15. An app may be able to ... |
| CVE-2024-45415 | CRITICAL | 9.8 | 0.5% | Sep 16, 2024 | The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity functio... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now