2024 CVE Vulnerabilities
39,242 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34009 | HIGH | 7.5 | 0.4% | May 31, 2024 | Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not ... |
| CVE-2024-34008 | HIGH | 8.8 | 0.3% | May 31, 2024 | Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk. |
| CVE-2024-34007 | HIGH | 8.8 | 0.3% | May 31, 2024 | The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged o... |
| CVE-2024-34006 | MEDIUM | 4.3 | 0.4% | May 31, 2024 | The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in... |
| CVE-2024-34005 | MEDIUM | 6.5 | 0.5% | May 31, 2024 | In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with ... |
| CVE-2024-34004 | MEDIUM | 6.5 | 0.5% | May 31, 2024 | In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with ... |
| CVE-2024-34003 | MEDIUM | 5.9 | 0.4% | May 31, 2024 | In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with ... |
| CVE-2024-34002 | MEDIUM | 6.5 | 0.5% | May 31, 2024 | In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with ... |
| CVE-2024-36845 | MEDIUM | 4.3 | 0.5% | May 31, 2024 | An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (D... |
| CVE-2024-36844 | HIGH | 7.5 | 0.6% | May 31, 2024 | libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows atta... |
| CVE-2024-36843 | HIGH | 7.5 | 0.8% | May 31, 2024 | libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function. |
| CVE-2024-34001 | HIGH | 8.4 | 0.3% | May 31, 2024 | Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk. |
| CVE-2024-34000 | MEDIUM | 4.3 | 0.5% | May 31, 2024 | ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk. |
| CVE-2024-33999 | CRITICAL | 9.8 | 0.5% | May 31, 2024 | The referrer URL used by MFA required additional sanitizing, rather than being used directly. |
| CVE-2024-33998 | MEDIUM | 5.4 | 0.4% | May 31, 2024 | Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacti... |
| CVE-2024-33997 | MEDIUM | 6.1 | 0.4% | May 31, 2024 | Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another us... |
| CVE-2024-33996 | MEDIUM | 6.2 | 0.4% | May 31, 2024 | Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events w... |
| CVE-2024-5564 | HIGH | 8.1 | 1.2% | May 31, 2024 | A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManage... |
| CVE-2024-23316 | HIGH | 8.8 | 0.5% | May 31, 2024 | HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to s... |
| CVE-2024-5176 | CRITICAL | 9.4 | 0.5% | May 31, 2024 | Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services wi... |
| CVE-2024-5144 | — | — | — | May 31, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-4342. Reason: This candidate is a r... |
| CVE-2024-35196 | LOW | 2 | 0.6% | May 31, 2024 | Sentry is a developer-first error tracking and performance monitoring platform. Sentry's Slack integration incorrectly r... |
| CVE-2024-31030 | CRITICAL | 9.1 | 0.8% | May 31, 2024 | An issue in coap_msg.c in Keith Cullen's FreeCoAP v.0.7 allows remote attackers to cause a Denial of Service or potentia... |
| CVE-2024-29848 | HIGH | 7.2 | 64.4% | May 31, 2024 | An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, pri... |
| CVE-2024-29846 | HIGH | 8 | 8.5% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attac... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now