2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51998 | HIGH | 8.6 | 0.7% | Nov 8, 2024 | changedetection.io is a free open source web page change detection tool. The validation for the file URI scheme falls sh... |
| CVE-2024-47072 | HIGH | 7.5 | 2.0% | Nov 8, 2024 | XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker t... |
| CVE-2024-46961 | HIGH | 8.1 | 0.4% | Nov 7, 2024 | The Inshot com.downloader.privatebrowser (aka Video Downloader - XDownloader) application through 1.3.5 for Android allo... |
| CVE-2024-46960 | HIGH | 8.8 | 0.4% | Nov 7, 2024 | The ASD com.rocks.video.downloader (aka HD Video Downloader All Format) application through 7.0.129 for Android allows a... |
| CVE-2024-36063 | HIGH | 7.5 | 0.3% | Nov 7, 2024 | The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no p... |
| CVE-2024-10975 | HIGH | 7.7 | 0.5% | Nov 7, 2024 | Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume cr... |
| CVE-2024-51995 | HIGH | 7.1 | 0.4% | Nov 7, 2024 | Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specif... |
| CVE-2024-51989 | HIGH | 7.1 | 0.3% | Nov 7, 2024 | Password Pusher is an open source application to communicate sensitive information over the web. A cross-site scripting ... |
| CVE-2024-51428 | HIGH | 7.5 | 0.5% | Nov 7, 2024 | An issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a crafted data channel pack... |
| CVE-2024-45794 | HIGH | 8.8 | 0.7% | Nov 7, 2024 | devtron is an open source tool integration platform for Kubernetes. In affected versions an authenticated user (with min... |
| CVE-2024-10967 | HIGH | 7.5 | 0.7% | Nov 7, 2024 | A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an ... |
| CVE-2024-10966 | HIGH | 8.8 | 3.1% | Nov 7, 2024 | A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by th... |
| CVE-2024-48953 | HIGH | 7.5 | 0.3% | Nov 7, 2024 | An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authenticatio... |
| CVE-2024-48951 | HIGH | 7.5 | 0.3% | Nov 7, 2024 | An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoin... |
| CVE-2024-48950 | HIGH | 7.5 | 0.3% | Nov 7, 2024 | An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing u... |
| CVE-2024-40715 | HIGH | 7.7 | 0.6% | Nov 7, 2024 | A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform ... |
| CVE-2024-10963 | HIGH | 7.4 | 0.8% | Nov 7, 2024 | A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This ... |
| CVE-2024-10668 | HIGH | 7.5 | 0.4% | Nov 7, 2024 | There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root... |
| CVE-2024-43440 | HIGH | 7.5 | 0.6% | Nov 7, 2024 | A flaw was found in moodle. A local file may include risks when restoring block backups. |
| CVE-2024-43438 | HIGH | 7.5 | 0.5% | Nov 7, 2024 | A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients ... |
| CVE-2024-43436 | HIGH | 7.2 | 0.6% | Nov 7, 2024 | A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators. |
| CVE-2024-43434 | HIGH | 8.1 | 0.6% | Nov 7, 2024 | The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check,... |
| CVE-2024-43431 | HIGH | 7.5 | 0.5% | Nov 7, 2024 | A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does n... |
| CVE-2024-43428 | HIGH | 7.1 | 0.2% | Nov 7, 2024 | To address a cache poisoning risk in Moodle, additional validation for local storage was required. |
| CVE-2024-43426 | HIGH | 7.5 | 0.6% | Nov 7, 2024 | A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk o... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now