2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-51998HIGH8.6changedetection.io is a free open source web page change detection tool. The validation for the file URI scheme falls sh...
CVE-2024-47072HIGH7.5XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker t...
CVE-2024-46961HIGH8.1The Inshot com.downloader.privatebrowser (aka Video Downloader - XDownloader) application through 1.3.5 for Android allo...
CVE-2024-46960HIGH8.8The ASD com.rocks.video.downloader (aka HD Video Downloader All Format) application through 7.0.129 for Android allows a...
CVE-2024-36063HIGH7.5The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no p...
CVE-2024-10975HIGH7.7Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume cr...
CVE-2024-51995HIGH7.1Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specif...
CVE-2024-51989HIGH7.1Password Pusher is an open source application to communicate sensitive information over the web. A cross-site scripting ...
CVE-2024-51428HIGH7.5An issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a crafted data channel pack...
CVE-2024-45794HIGH8.8devtron is an open source tool integration platform for Kubernetes. In affected versions an authenticated user (with min...
CVE-2024-10967HIGH7.5A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an ...
CVE-2024-10966HIGH8.8A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by th...
CVE-2024-48953HIGH7.5An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authenticatio...
CVE-2024-48951HIGH7.5An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoin...
CVE-2024-48950HIGH7.5An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing u...
CVE-2024-40715HIGH7.7A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform ...
CVE-2024-10963HIGH7.4A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This ...
CVE-2024-10668HIGH7.5There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root...
CVE-2024-43440HIGH7.5A flaw was found in moodle. A local file may include risks when restoring block backups.
CVE-2024-43438HIGH7.5A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients ...
CVE-2024-43436HIGH7.2A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.
CVE-2024-43434HIGH8.1The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check,...
CVE-2024-43431HIGH7.5A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does n...
CVE-2024-43428HIGH7.1To address a cache poisoning risk in Moodle, additional validation for local storage was required.
CVE-2024-43426HIGH7.5A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk o...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now