2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3370 | HIGH | 8.8 | 0.3% | Nov 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egebilgi Software ... |
| CVE-2024-42392 | HIGH | 7.5 | 0.2% | Nov 18, 2024 | Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite l... |
| CVE-2024-42386 | HIGH | 7.5 | 0.4% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex... |
| CVE-2024-42385 | HIGH | 7 | 0.1% | Nov 18, 2024 | Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bou... |
| CVE-2024-42384 | HIGH | 7.5 | 0.5% | Nov 18, 2024 | Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpect... |
| CVE-2024-41974 | HIGH | 7.1 | 0.3% | Nov 18, 2024 | A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for cri... |
| CVE-2024-41973 | HIGH | 8.1 | 0.6% | Nov 18, 2024 | A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file wri... |
| CVE-2024-41971 | HIGH | 8.1 | 0.6% | Nov 18, 2024 | A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss. |
| CVE-2024-48962 | HIGH | 8.8 | 0.6% | Nov 18, 2024 | Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization ... |
| CVE-2024-45791 | HIGH | 7.5 | 0.8% | Nov 18, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache... |
| CVE-2024-45505 | HIGH | 8.8 | 2.1% | Nov 18, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (i... |
| CVE-2024-41969 | HIGH | 8.8 | 0.5% | Nov 18, 2024 | A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication... |
| CVE-2024-41967 | HIGH | 8.1 | 0.4% | Nov 18, 2024 | A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of ... |
| CVE-2024-41151 | HIGH | 8.8 | 1.0% | Nov 18, 2024 | Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by author... |
| CVE-2024-49574 | HIGH | 8.8 | 1.7% | Nov 18, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module. |
| CVE-2024-22067 | HIGH | 8.8 | 0.7% | Nov 18, 2024 | ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web modul... |
| CVE-2024-52946 | HIGH | 8.8 | 0.5% | Nov 18, 2024 | An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated... |
| CVE-2024-52945 | HIGH | 7.8 | 0.2% | Nov 18, 2024 | An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows... |
| CVE-2024-11310 | HIGH | 7.5 | 0.7% | Nov 18, 2024 | The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulner... |
| CVE-2024-11309 | HIGH | 7.5 | 0.7% | Nov 18, 2024 | The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulner... |
| CVE-2024-52940 | HIGH | 7.5 | 1.2% | Nov 18, 2024 | AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address wi... |
| CVE-2024-43704 | HIGH | 8.4 | 0.2% | Nov 18, 2024 | Software installed and run as a non-privileged user may conduct improper GPU system calls to gain access to the graphics... |
| CVE-2024-52920 | HIGH | 7.5 | 0.6% | Nov 18, 2024 | Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA ... |
| CVE-2024-52916 | HIGH | 7.5 | 0.5% | Nov 18, 2024 | Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty h... |
| CVE-2024-52915 | HIGH | 7.5 | 0.6% | Nov 18, 2024 | Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV m... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now