2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1867 | HIGH | 7.8 | 0.4% | Nov 22, 2024 | G DATA Total Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers... |
| CVE-2024-52726 | HIGH | 7.5 | 1.6% | Nov 22, 2024 | CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensiti... |
| CVE-2024-11618 | HIGH | 7.3 | 0.6% | Nov 22, 2024 | A vulnerability classified as critical was found in IPC Unigy Management System 04.03.00.08.0027. Affected by this vulne... |
| CVE-2024-44786 | HIGH | 7.5 | 0.5% | Nov 22, 2024 | Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vecto... |
| CVE-2024-10220 | HIGH | 8.1 | 3.0% | Nov 22, 2024 | The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue aff... |
| CVE-2024-52804 | HIGH | 7.5 | 1.1% | Nov 22, 2024 | Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in To... |
| CVE-2024-52802 | HIGH | 7.5 | 0.7% | Nov 22, 2024 | RIOT is an operating system for internet of things (IoT) devices. In version 2024.04 and prior, the function `_parse_adv... |
| CVE-2024-50401 | HIGH | 7.2 | 0.6% | Nov 22, 2024 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2024-50400 | HIGH | 7.2 | 0.6% | Nov 22, 2024 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2024-50399 | HIGH | 7.2 | 0.6% | Nov 22, 2024 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2024-50398 | HIGH | 7.2 | 0.6% | Nov 22, 2024 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2024-50397 | HIGH | 8.8 | 0.7% | Nov 22, 2024 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2024-50396 | HIGH | 8.8 | 0.6% | Nov 22, 2024 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2024-50395 | HIGH | 8.8 | 1.3% | Nov 22, 2024 | An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If... |
| CVE-2024-48861 | HIGH | 7.8 | 0.8% | Nov 22, 2024 | An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerabil... |
| CVE-2024-38647 | HIGH | 7.5 | 0.6% | Nov 22, 2024 | An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerabi... |
| CVE-2024-38644 | HIGH | 8.8 | 1.6% | Nov 22, 2024 | An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could... |
| CVE-2024-37044 | HIGH | 7.2 | 0.8% | Nov 22, 2024 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2024-37041 | HIGH | 7.2 | 0.8% | Nov 22, 2024 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2024-41779 | HIGH | 8.1 | 0.8% | Nov 22, 2024 | IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security... |
| CVE-2024-7837 | HIGH | 8.2 | 0.4% | Nov 22, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Firmanet Software ... |
| CVE-2024-11601 | HIGH | 8.1 | 0.3% | Nov 22, 2024 | The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Slider... |
| CVE-2024-11104 | HIGH | 8.1 | 0.7% | Nov 22, 2024 | The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Slider... |
| CVE-2024-31408 | HIGH | 8 | 1.1% | Nov 22, 2024 | OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker... |
| CVE-2024-52052 | HIGH | 7.2 | 0.5% | Nov 21, 2024 | Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom ap... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now