2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41874 | CRITICAL | 9.8 | 30.3% | Sep 13, 2024 | ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that c... |
| CVE-2024-6656 | CRITICAL | 9.8 | 0.4% | Sep 13, 2024 | Use of Hard-coded Credentials vulnerability in TNB Mobile Solutions Cockpit Software allows Read Sensitive Strings Withi... |
| CVE-2024-8762 | CRITICAL | 9.8 | 0.7% | Sep 13, 2024 | A vulnerability was found in code-projects Crud Operation System 1.0. It has been classified as critical. This affects a... |
| CVE-2024-7961 | CRITICAL | 9.8 | 1.0% | Sep 12, 2024 | A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could... |
| CVE-2024-7960 | CRITICAL | 9.1 | 0.5% | Sep 12, 2024 | The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive informati... |
| CVE-2024-8696 | CRITICAL | 9.8 | 1.2% | Sep 12, 2024 | A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a mal... |
| CVE-2024-8695 | CRITICAL | 9.8 | 1.3% | Sep 12, 2024 | A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious e... |
| CVE-2024-2743 | CRITICAL | 9.1 | 0.4% | Sep 12, 2024 | An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.... |
| CVE-2024-45823 | CRITICAL | 9.8 | 0.5% | Sep 12, 2024 | CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists... |
| CVE-2024-45824 | CRITICAL | 9.8 | 1.3% | Sep 12, 2024 | CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chai... |
| CVE-2024-40457 | CRITICAL | 9.1 | 0.7% | Sep 12, 2024 | No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: t... |
| CVE-2024-29847 | CRITICAL | 9.8 | 52.9% | Sep 12, 2024 | Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows... |
| CVE-2024-8692 | CRITICAL | 9.8 | 0.5% | Sep 11, 2024 | A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an ... |
| CVE-2024-44541 | CRITICAL | 9.8 | 2.6% | Sep 11, 2024 | evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action... |
| CVE-2024-44466 | CRITICAL | 9.8 | 10.7% | Sep 11, 2024 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request mes... |
| CVE-2024-27115 | CRITICAL | 9.8 | 4.6% | Sep 11, 2024 | A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this ... |
| CVE-2024-27114 | CRITICAL | 9.8 | 0.5% | Sep 11, 2024 | A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the pub... |
| CVE-2024-27113 | CRITICAL | 9.8 | 0.4% | Sep 11, 2024 | An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that o... |
| CVE-2024-27112 | CRITICAL | 9.8 | 0.4% | Sep 11, 2024 | A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabl... |
| CVE-2024-6091 | CRITICAL | 9.8 | 0.8% | Sep 11, 2024 | A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist s... |
| CVE-2024-45790 | CRITICAL | 9.8 | 0.6% | Sep 11, 2024 | This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authenticati... |
| CVE-2024-8277 | CRITICAL | 9.8 | 1.6% | Sep 11, 2024 | The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to,... |
| CVE-2024-8191 | CRITICAL | 9.8 | 19.6% | Sep 10, 2024 | SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unau... |
| CVE-2024-8503 | CRITICAL | 9.8 | 79.1% | Sep 10, 2024 | An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database reco... |
| CVE-2024-43040 | CRITICAL | 9.1 | 0.4% | Sep 10, 2024 | Renwoxing Enterprise Intelligent Management System before v3.0 was discovered to contain a SQL injection vulnerability v... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now