2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49360 | HIGH | 8.4 | 0.5% | Nov 29, 2024 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. An authenticat... |
| CVE-2024-36623 | HIGH | 8.1 | 0.6% | Nov 29, 2024 | moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger mult... |
| CVE-2024-49804 | HIGH | 7.8 | 0.2% | Nov 29, 2024 | IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non-administrative user... |
| CVE-2024-49803 | HIGH | 8.8 | 0.8% | Nov 29, 2024 | IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitr... |
| CVE-2024-11983 | HIGH | 7.2 | 1.1% | Nov 29, 2024 | Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers wit... |
| CVE-2024-11982 | HIGH | 7.2 | 0.6% | Nov 29, 2024 | Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers wi... |
| CVE-2024-11481 | HIGH | 8.2 | 0.4% | Nov 29, 2024 | A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper han... |
| CVE-2024-11013 | HIGH | 7.2 | 1.1% | Nov 29, 2024 | Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27,... |
| CVE-2024-11981 | HIGH | 7.5 | 0.5% | Nov 29, 2024 | Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated atta... |
| CVE-2024-11980 | HIGH | 8.6 | 0.5% | Nov 29, 2024 | Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated rem... |
| CVE-2024-48651 | HIGH | 7.5 | 2.2% | Nov 29, 2024 | In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of th... |
| CVE-2024-54124 | HIGH | 8.8 | 0.4% | Nov 29, 2024 | In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen. |
| CVE-2024-11978 | HIGH | 7.5 | 0.7% | Nov 29, 2024 | DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this ... |
| CVE-2024-9852 | HIGH | 7.8 | 0.2% | Nov 28, 2024 | Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi E... |
| CVE-2024-8300 | HIGH | 7 | 0.2% | Nov 28, 2024 | Dead Code vulnerability in Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsub... |
| CVE-2024-8299 | HIGH | 7.8 | 0.2% | Nov 28, 2024 | Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi E... |
| CVE-2024-11968 | HIGH | 7.5 | 0.5% | Nov 28, 2024 | A vulnerability was found in code-projects Farmacia up to 1.0. It has been declared as critical. Affected by this vulner... |
| CVE-2024-11969 | HIGH | 8.8 | 0.2% | Nov 28, 2024 | The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerabili... |
| CVE-2024-11963 | HIGH | 8.8 | 0.6% | Nov 28, 2024 | A vulnerability, which was classified as critical, has been found in code-projects Responsive Hotel Site 1.0. Affected b... |
| CVE-2024-11961 | HIGH | 7.5 | 0.9% | Nov 28, 2024 | A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms 3.7. It has been rated as problematic. This i... |
| CVE-2024-11960 | HIGH | 8.8 | 1.7% | Nov 28, 2024 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the f... |
| CVE-2024-11959 | HIGH | 8.8 | 1.7% | Nov 28, 2024 | A vulnerability was found in D-Link DIR-605L 2.13B01. It has been classified as critical. This affects the function form... |
| CVE-2024-53736 | HIGH | 7.1 | 0.2% | Nov 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Jason Grim Custom Shortcode Sidebars custom-shortcode-sidebars allows... |
| CVE-2024-53734 | HIGH | 7.1 | 0.2% | Nov 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Jamie O Idealien Category Enhancements idealien-category-enhancements... |
| CVE-2024-53733 | HIGH | 7.1 | 0.3% | Nov 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in harshtohit111 Fenc... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now