2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11998 | HIGH | 7.5 | 0.4% | Nov 30, 2024 | A vulnerability was found in code-projects Farmacia 1.0. It has been declared as critical. This vulnerability affects un... |
| CVE-2024-43703 | HIGH | 8.1 | 0.4% | Nov 30, 2024 | Software installed and run as a non-privileged user may conduct improper GPU system calls to achieve unauthorised reads ... |
| CVE-2024-43702 | HIGH | 8.1 | 0.3% | Nov 30, 2024 | Software installed and run as a non-privileged user may conduct improper GPU system calls to allow unprivileged access t... |
| CVE-2024-53623 | HIGH | 7.5 | 0.4% | Nov 29, 2024 | Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive informa... |
| CVE-2024-36612 | HIGH | 7.5 | 0.6% | Nov 29, 2024 | Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers. |
| CVE-2024-35371 | HIGH | 7.5 | 0.5% | Nov 29, 2024 | Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient... |
| CVE-2024-53980 | HIGH | 7.5 | 0.7% | Nov 29, 2024 | RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ... |
| CVE-2024-53979 | HIGH | 8.2 | 0.1% | Nov 29, 2024 | ibm.ibm_zhmc is an Ansible collection for the IBM Z HMC. The Ansible collection "ibm.ibm_zhmc" writes password-like prop... |
| CVE-2024-53865 | HIGH | 8.2 | 0.1% | Nov 29, 2024 | zhmcclient is a pure Python client library for the IBM Z HMC Web Services API. In affected versions the Python package "... |
| CVE-2024-53861 | HIGH | 7.5 | 0.8% | Nov 29, 2024 | pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting ... |
| CVE-2024-53848 | HIGH | 7.1 | 0.1% | Nov 29, 2024 | check-jsonschema is a CLI and set of pre-commit hooks for jsonschema validation. The default cache strategy uses the bas... |
| CVE-2024-36611 | HIGH | 7.5 | 0.8% | Nov 29, 2024 | In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to ad... |
| CVE-2024-49360 | HIGH | 8.4 | 0.5% | Nov 29, 2024 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. An authenticat... |
| CVE-2024-36623 | HIGH | 8.1 | 0.6% | Nov 29, 2024 | moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger mult... |
| CVE-2024-49804 | HIGH | 7.8 | 0.2% | Nov 29, 2024 | IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non-administrative user... |
| CVE-2024-49803 | HIGH | 8.8 | 0.8% | Nov 29, 2024 | IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitr... |
| CVE-2024-11983 | HIGH | 7.2 | 1.1% | Nov 29, 2024 | Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers wit... |
| CVE-2024-11982 | HIGH | 7.2 | 0.6% | Nov 29, 2024 | Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers wi... |
| CVE-2024-11481 | HIGH | 8.2 | 0.4% | Nov 29, 2024 | A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper han... |
| CVE-2024-11013 | HIGH | 7.2 | 1.1% | Nov 29, 2024 | Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27,... |
| CVE-2024-11981 | HIGH | 7.5 | 0.5% | Nov 29, 2024 | Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated atta... |
| CVE-2024-11980 | HIGH | 8.6 | 0.5% | Nov 29, 2024 | Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated rem... |
| CVE-2024-48651 | HIGH | 7.5 | 2.2% | Nov 29, 2024 | In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of th... |
| CVE-2024-54124 | HIGH | 8.8 | 0.4% | Nov 29, 2024 | In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen. |
| CVE-2024-11978 | HIGH | 7.5 | 0.7% | Nov 29, 2024 | DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now