2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41967 | HIGH | 8.1 | 0.4% | Nov 18, 2024 | A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of ... |
| CVE-2024-41151 | HIGH | 8.8 | 1.0% | Nov 18, 2024 | Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by author... |
| CVE-2024-49574 | HIGH | 8.8 | 1.7% | Nov 18, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module. |
| CVE-2024-22067 | HIGH | 8.8 | 0.7% | Nov 18, 2024 | ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web modul... |
| CVE-2024-52946 | HIGH | 8.8 | 0.5% | Nov 18, 2024 | An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated... |
| CVE-2024-52945 | HIGH | 7.8 | 0.2% | Nov 18, 2024 | An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows... |
| CVE-2024-11310 | HIGH | 7.5 | 0.7% | Nov 18, 2024 | The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulner... |
| CVE-2024-11309 | HIGH | 7.5 | 0.7% | Nov 18, 2024 | The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulner... |
| CVE-2024-52940 | HIGH | 7.5 | 1.2% | Nov 18, 2024 | AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address wi... |
| CVE-2024-43704 | HIGH | 8.4 | 0.2% | Nov 18, 2024 | Software installed and run as a non-privileged user may conduct improper GPU system calls to gain access to the graphics... |
| CVE-2024-52920 | HIGH | 7.5 | 0.6% | Nov 18, 2024 | Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA ... |
| CVE-2024-52916 | HIGH | 7.5 | 0.5% | Nov 18, 2024 | Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty h... |
| CVE-2024-52915 | HIGH | 7.5 | 0.6% | Nov 18, 2024 | Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV m... |
| CVE-2024-52914 | HIGH | 7.5 | 0.5% | Nov 18, 2024 | In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed tr... |
| CVE-2024-52912 | HIGH | 7.5 | 0.5% | Nov 18, 2024 | Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offse... |
| CVE-2024-0793 | HIGH | 7.7 | 0.6% | Nov 17, 2024 | A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking... |
| CVE-2024-52876 | HIGH | 7.5 | 0.5% | Nov 17, 2024 | Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows una... |
| CVE-2024-52872 | HIGH | 7.5 | 0.4% | Nov 17, 2024 | In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions. |
| CVE-2024-52871 | HIGH | 7.5 | 0.4% | Nov 17, 2024 | In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting. |
| CVE-2024-52867 | HIGH | 8.1 | 0.2% | Nov 17, 2024 | guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users b... |
| CVE-2024-52415 | HIGH | 8.8 | 0.2% | Nov 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in skipstorm SK WP Settings Backup sk-wp-settings-backup allows Object I... |
| CVE-2024-9887 | HIGH | 7.2 | 0.5% | Nov 16, 2024 | The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via th... |
| CVE-2024-10645 | HIGH | 7.5 | 0.5% | Nov 16, 2024 | The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘br’ parameter in ... |
| CVE-2024-10728 | HIGH | 8.8 | 36.5% | Nov 16, 2024 | The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plug... |
| CVE-2024-9935 | HIGH | 7.5 | 7.5% | Nov 16, 2024 | The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now