2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34009HIGH7.5Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not ...
CVE-2024-34008HIGH8.8Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.
CVE-2024-34007HIGH8.8The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged o...
CVE-2024-34006MEDIUM4.3The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in...
CVE-2024-34005MEDIUM6.5In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with ...
CVE-2024-34004MEDIUM6.5In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with ...
CVE-2024-34003MEDIUM5.9In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with ...
CVE-2024-34002MEDIUM6.5In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with ...
CVE-2024-36845MEDIUM4.3An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (D...
CVE-2024-36844HIGH7.5libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows atta...
CVE-2024-36843HIGH7.5libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function.
CVE-2024-34001HIGH8.4Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.
CVE-2024-34000MEDIUM4.3ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.
CVE-2024-33999CRITICAL9.8The referrer URL used by MFA required additional sanitizing, rather than being used directly.
CVE-2024-33998MEDIUM5.4Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacti...
CVE-2024-33997MEDIUM6.1Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another us...
CVE-2024-33996MEDIUM6.2Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events w...
CVE-2024-5564HIGH8.1A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManage...
CVE-2024-23316HIGH8.8HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to s...
CVE-2024-5176CRITICAL9.4Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services wi...
CVE-2024-5144Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-4342. Reason: This candidate is a r...
CVE-2024-35196LOW2Sentry is a developer-first error tracking and performance monitoring platform. Sentry's Slack integration incorrectly r...
CVE-2024-31030CRITICAL9.1An issue in coap_msg.c in Keith Cullen's FreeCoAP v.0.7 allows remote attackers to cause a Denial of Service or potentia...
CVE-2024-29848HIGH7.2An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, pri...
CVE-2024-29846HIGH8An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attac...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now