2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45409 | CRITICAL | 9.8 | 10.7% | Sep 10, 2024 | The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.... |
| CVE-2024-44893 | CRITICAL | 9.8 | 0.5% | Sep 10, 2024 | An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via... |
| CVE-2024-43491 | CRITICAL | 9.8 | 12.1% | Sep 10, 2024 | Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecti... |
| CVE-2024-43455 | CRITICAL | 9.8 | 1.7% | Sep 10, 2024 | Windows Remote Desktop Licensing Service Spoofing Vulnerability |
| CVE-2024-38240 | CRITICAL | 9.8 | 1.5% | Sep 10, 2024 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
| CVE-2024-38225 | CRITICAL | 9.8 | 1.4% | Sep 10, 2024 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability |
| CVE-2024-38220 | CRITICAL | 9 | 1.0% | Sep 10, 2024 | Azure Stack Hub Elevation of Privilege Vulnerability |
| CVE-2024-38216 | CRITICAL | 9 | 0.9% | Sep 10, 2024 | Azure Stack Hub Elevation of Privilege Vulnerability |
| CVE-2024-38194 | CRITICAL | 9.9 | 1.3% | Sep 10, 2024 | An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges ov... |
| CVE-2024-37980 | CRITICAL | 9.8 | 1.4% | Sep 10, 2024 | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2024-37341 | CRITICAL | 9.8 | 1.4% | Sep 10, 2024 | Microsoft SQL Server Elevation of Privilege Vulnerability |
| CVE-2024-21416 | CRITICAL | 9.8 | 1.4% | Sep 10, 2024 | Windows TCP/IP Remote Code Execution Vulnerability |
| CVE-2024-45595 | CRITICAL | 9.8 | 0.7% | Sep 10, 2024 | D-Tale is a visualizer for Pandas data structures. Users hosting D-Tale publicly can be vulnerable to remote code execut... |
| CVE-2024-44677 | CRITICAL | 9.8 | 0.5% | Sep 10, 2024 | eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrar... |
| CVE-2024-8654 | CRITICAL | 9.8 | 0.4% | Sep 10, 2024 | MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are calle... |
| CVE-2024-40754 | CRITICAL | 9.8 | 0.5% | Sep 10, 2024 | Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This ... |
| CVE-2024-45032 | CRITICAL | 10 | 0.8% | Sep 10, 2024 | A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Managemen... |
| CVE-2024-44087 | CRITICAL | 9.2 | 10.6% | Sep 10, 2024 | A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6.0 (Al... |
| CVE-2024-41171 | CRITICAL | 9.3 | 0.1% | Sep 10, 2024 | A vulnerability has been identified in SINUMERIK 828D V4 (All versions), SINUMERIK 828D V5 (All versions < V5.24), SINUM... |
| CVE-2024-37995 | CRITICAL | 9.1 | 0.3% | Sep 10, 2024 | A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC R... |
| CVE-2024-35783 | CRITICAL | 9.4 | 0.6% | Sep 10, 2024 | A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions ... |
| CVE-2024-33698 | CRITICAL | 9.8 | 1.1% | Sep 10, 2024 | A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SI... |
| CVE-2024-39583 | CRITICAL | 9.8 | 0.3% | Sep 10, 2024 | Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a Use of a Broken or Risky Cryptographic Algorithm vulnera... |
| CVE-2024-39581 | CRITICAL | 9.8 | 0.4% | Sep 10, 2024 | Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulne... |
| CVE-2024-6596 | CRITICAL | 9.8 | 0.8% | Sep 10, 2024 | An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users c... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now