2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53675 | HIGH | 7.5 | 83.9% | Nov 26, 2024 | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in... |
| CVE-2024-53674 | HIGH | 7.5 | 47.4% | Nov 26, 2024 | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in... |
| CVE-2024-11622 | HIGH | 7.5 | 1.5% | Nov 26, 2024 | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in... |
| CVE-2024-8676 | HIGH | 7.4 | 0.8% | Nov 26, 2024 | A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be a... |
| CVE-2024-49053 | HIGH | 7.6 | 0.7% | Nov 26, 2024 | Microsoft Dynamics 365 Sales Spoofing Vulnerability |
| CVE-2024-8237 | HIGH | 7.5 | 0.6% | Nov 26, 2024 | A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 12.6 prior to 17.4.5... |
| CVE-2024-8177 | HIGH | 7.5 | 0.6% | Nov 26, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 pr... |
| CVE-2024-8114 | HIGH | 8.8 | 0.7% | Nov 26, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.... |
| CVE-2024-52008 | HIGH | 8.8 | 0.5% | Nov 26, 2024 | Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password... |
| CVE-2024-32965 | HIGH | 8.6 | 23.7% | Nov 26, 2024 | Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnera... |
| CVE-2024-11828 | HIGH | 7.5 | 0.6% | Nov 26, 2024 | A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17.... |
| CVE-2024-11669 | HIGH | 7.5 | 0.5% | Nov 26, 2024 | An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 b... |
| CVE-2024-53555 | HIGH | 8.8 | 0.7% | Nov 26, 2024 | A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV fil... |
| CVE-2024-11407 | HIGH | 7.5 | 0.6% | Nov 26, 2024 | There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled ... |
| CVE-2024-52336 | HIGH | 7.8 | 0.3% | Nov 26, 2024 | A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be call... |
| CVE-2024-36463 | HIGH | 8.8 | 0.8% | Nov 26, 2024 | The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal... |
| CVE-2024-9461 | HIGH | 7.2 | 1.0% | Nov 26, 2024 | The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remo... |
| CVE-2024-11702 | HIGH | 7.5 | 0.5% | Nov 26, 2024 | Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored da... |
| CVE-2024-11700 | HIGH | 8.1 | 0.5% | Nov 26, 2024 | Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to use... |
| CVE-2024-11699 | HIGH | 8.8 | 0.7% | Nov 26, 2024 | Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence ... |
| CVE-2024-11697 | HIGH | 8.8 | 0.8% | Nov 26, 2024 | When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?"... |
| CVE-2024-11691 | HIGH | 8.8 | 0.7% | Nov 26, 2024 | Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corrupti... |
| CVE-2024-51569 | HIGH | 7.5 | 1.2% | Nov 26, 2024 | Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could l... |
| CVE-2024-38831 | HIGH | 7.8 | 0.3% | Nov 26, 2024 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative... |
| CVE-2024-38830 | HIGH | 7.8 | 0.2% | Nov 26, 2024 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now