2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54003 | HIGH | 8 | 77.5% | Nov 27, 2024 | Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting ... |
| CVE-2024-31976 | HIGH | 8 | 1.0% | Nov 27, 2024 | EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controll... |
| CVE-2024-53920 | HIGH | 7.8 | 0.6% | Nov 27, 2024 | In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) ... |
| CVE-2024-52951 | HIGH | 8 | 1.1% | Nov 27, 2024 | Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authent... |
| CVE-2024-53603 | HIGH | 7.3 | 0.7% | Nov 27, 2024 | A SQL Injection vulnerability was found in /covid-tms/password-recovery.php in PHPGurukul COVID 19 Testing Management Sy... |
| CVE-2024-36468 | HIGH | 8.2 | 0.5% | Nov 27, 2024 | The reported vulnerability is a stack buffer overflow in the zbx_snmp_cache_handle_engineid function within the Zabbix s... |
| CVE-2024-52323 | HIGH | 8.1 | 1.1% | Nov 27, 2024 | Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which a... |
| CVE-2024-36467 | HIGH | 8.8 | 0.7% | Nov 27, 2024 | An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the u... |
| CVE-2024-52959 | HIGH | 7.2 | 0.6% | Nov 27, 2024 | A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversation... |
| CVE-2024-52958 | HIGH | 7.2 | 0.3% | Nov 27, 2024 | A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platfo... |
| CVE-2024-11219 | HIGH | 7.5 | 0.5% | Nov 27, 2024 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path ... |
| CVE-2024-5921 | HIGH | 8.8 | 1.5% | Nov 27, 2024 | An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect ... |
| CVE-2024-53675 | HIGH | 7.5 | 83.9% | Nov 26, 2024 | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in... |
| CVE-2024-53674 | HIGH | 7.5 | 47.4% | Nov 26, 2024 | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in... |
| CVE-2024-11622 | HIGH | 7.5 | 1.5% | Nov 26, 2024 | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in... |
| CVE-2024-8676 | HIGH | 7.4 | 0.8% | Nov 26, 2024 | A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be a... |
| CVE-2024-49053 | HIGH | 7.6 | 0.7% | Nov 26, 2024 | Microsoft Dynamics 365 Sales Spoofing Vulnerability |
| CVE-2024-8237 | HIGH | 7.5 | 0.6% | Nov 26, 2024 | A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 12.6 prior to 17.4.5... |
| CVE-2024-8177 | HIGH | 7.5 | 0.6% | Nov 26, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 pr... |
| CVE-2024-8114 | HIGH | 8.8 | 0.7% | Nov 26, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.... |
| CVE-2024-52008 | HIGH | 8.8 | 0.5% | Nov 26, 2024 | Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password... |
| CVE-2024-32965 | HIGH | 8.6 | 23.7% | Nov 26, 2024 | Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnera... |
| CVE-2024-11828 | HIGH | 7.5 | 0.6% | Nov 26, 2024 | A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17.... |
| CVE-2024-11669 | HIGH | 7.5 | 0.5% | Nov 26, 2024 | An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 b... |
| CVE-2024-53555 | HIGH | 8.8 | 0.7% | Nov 26, 2024 | A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV fil... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now