2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34729 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In multiple locations, there is a possible arbitrary code execution due to a logic error in the code. This could lead to... |
| CVE-2024-34719 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local esca... |
| CVE-2024-31337 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This... |
| CVE-2024-23715 | HIGH | 7.8 | 0.1% | Nov 13, 2024 | In PMRWritePMPageList of pmr.c, there is a possible out of bounds write due to a logic error in the code. This could lea... |
| CVE-2024-9413 | HIGH | 8 | 0.4% | Nov 13, 2024 | The transport_message_handler function in SCP-Firmware release versions 2.11.0-2.15.0 does not properly handle errors, p... |
| CVE-2024-52291 | HIGH | 7.2 | 1.1% | Nov 13, 2024 | Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system v... |
| CVE-2024-51996 | HIGH | 7.5 | 0.6% | Nov 13, 2024 | Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a p... |
| CVE-2024-52299 | HIGH | 7.5 | 0.5% | Nov 13, 2024 | macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFViewerService... |
| CVE-2024-52298 | HIGH | 7.5 | 0.7% | Nov 13, 2024 | macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The PDF Viewer macro allows an attacker to view an... |
| CVE-2024-52293 | HIGH | 7.2 | 1.3% | Nov 13, 2024 | Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function Fi... |
| CVE-2024-50972 | HIGH | 7.2 | 0.7% | Nov 13, 2024 | A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attacker... |
| CVE-2024-50971 | HIGH | 7.2 | 0.7% | Nov 13, 2024 | A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to... |
| CVE-2024-50970 | HIGH | 8.8 | 0.5% | Nov 13, 2024 | A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote atta... |
| CVE-2024-10013 | HIGH | 7.8 | 0.2% | Nov 13, 2024 | In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through... |
| CVE-2024-10012 | HIGH | 7.8 | 0.2% | Nov 13, 2024 | In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an i... |
| CVE-2024-50854 | HIGH | 8.8 | 0.5% | Nov 13, 2024 | Tenda G3 v3.0 v15.11.0.20 was discovered to contain a stack overflow via the formSetPortMapping function. |
| CVE-2024-50853 | HIGH | 8.8 | 1.6% | Nov 13, 2024 | Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function. |
| CVE-2024-50852 | HIGH | 8.8 | 1.6% | Nov 13, 2024 | Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount ... |
| CVE-2024-49506 | HIGH | 7.3 | 0.1% | Nov 13, 2024 | Insecure creation of temporary files allows local users on systems with non-default configurations to cause denial of se... |
| CVE-2024-49504 | HIGH | 7 | 0.3% | Nov 13, 2024 | grub2 allowed attackers with access to the grub shell to access files on the encrypted disks. |
| CVE-2024-48989 | HIGH | 7.5 | 0.5% | Nov 13, 2024 | A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacke... |
| CVE-2024-47574 | HIGH | 7.8 | 0.5% | Nov 13, 2024 | A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 ... |
| CVE-2024-4741 | HIGH | 7.5 | 2.9% | Nov 13, 2024 | Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously fre... |
| CVE-2024-9409 | HIGH | 7.5 | 0.8% | Nov 13, 2024 | CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive re... |
| CVE-2024-8937 | HIGH | 8.3 | 0.6% | Nov 13, 2024 | CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now