2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37285 | HIGH | 7.2 | 1.3% | Nov 14, 2024 | A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document con... |
| CVE-2024-52302 | HIGH | 8.7 | 3.2% | Nov 14, 2024 | common-user-management is a robust Spring Boot application featuring user management services designed to control user a... |
| CVE-2024-11214 | HIGH | 7.2 | 0.6% | Nov 14, 2024 | A vulnerability has been found in SourceCodester Best Employee Management System 1.0 and classified as critical. This vu... |
| CVE-2024-11213 | HIGH | 7.2 | 0.5% | Nov 14, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Best Employee Management System 1.0. This... |
| CVE-2024-11136 | HIGH | 8.2 | 0.2% | Nov 14, 2024 | The default TCL Camera application exposes a provider vulnerable to path traversal vulnerability. Malicious application ... |
| CVE-2024-10921 | HIGH | 8.1 | 0.5% | Nov 14, 2024 | An authorized user may trigger crashes or receive the contents of buffer over-reads of Server memory by issuing speciall... |
| CVE-2024-11212 | HIGH | 8.8 | 0.6% | Nov 14, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Best Employee Management System 1.0.... |
| CVE-2024-11211 | HIGH | 7.2 | 0.6% | Nov 14, 2024 | A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the com... |
| CVE-2024-9633 | HIGH | 7.5 | 0.4% | Nov 14, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.4.2, all versions start... |
| CVE-2024-11208 | HIGH | 8.1 | 0.7% | Nov 14, 2024 | A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functi... |
| CVE-2024-10962 | HIGH | 8.8 | 0.6% | Nov 14, 2024 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up t... |
| CVE-2024-10979 | HIGH | 8.8 | 4.4% | Nov 14, 2024 | Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitiv... |
| CVE-2024-7730 | HIGH | 7.8 | 0.3% | Nov 14, 2024 | A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input call... |
| CVE-2024-45670 | HIGH | 8.1 | 0.3% | Nov 14, 2024 | IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowi... |
| CVE-2024-9693 | HIGH | 8.8 | 0.5% | Nov 14, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 pr... |
| CVE-2024-9472 | HIGH | 8.7 | 0.4% | Nov 14, 2024 | A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Series, PA-3200 Series, PA-5200 Series, and P... |
| CVE-2024-50305 | HIGH | 7.5 | 0.9% | Nov 14, 2024 | Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic S... |
| CVE-2024-47916 | HIGH | 7.5 | 0.5% | Nov 14, 2024 | Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2024-47915 | HIGH | 7.5 | 0.4% | Nov 14, 2024 | VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2024-45254 | HIGH | 7.5 | 0.4% | Nov 14, 2024 | VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2024-45253 | HIGH | 7.5 | 0.5% | Nov 14, 2024 | Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2024-38479 | HIGH | 7.5 | 0.9% | Nov 14, 2024 | Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 ... |
| CVE-2024-2551 | HIGH | 7.5 | 0.5% | Nov 14, 2024 | A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to st... |
| CVE-2024-2550 | HIGH | 7.5 | 0.5% | Nov 14, 2024 | A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an u... |
| CVE-2024-11206 | HIGH | 7.5 | 0.4% | Nov 14, 2024 | Unauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user info... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now