2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43425 | HIGH | 8.1 | 83.3% | Nov 7, 2024 | A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated que... |
| CVE-2024-24914 | HIGH | 8 | 0.4% | Nov 7, 2024 | Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix t... |
| CVE-2024-10526 | HIGH | 8.6 | 0.2% | Nov 7, 2024 | Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation ... |
| CVE-2024-50164 | HIGH | 7.1 | 0.2% | Nov 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix overloading of MEM_UNINIT's meaning Lonia... |
| CVE-2024-50159 | HIGH | 7.8 | 0.2% | Nov 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix the double free in scmi_deb... |
| CVE-2024-50158 | HIGH | 7.8 | 0.2% | Nov 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix out of bound check Driver export... |
| CVE-2024-50155 | HIGH | 7.8 | 0.2% | Nov 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: netdevsim: use cond_resched() in nsim_dev_trap_repo... |
| CVE-2024-50154 | HIGH | 7 | 0.2% | Nov 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: tcp/dccp: Don't use timer_pending() in reqsk_queue_... |
| CVE-2024-50151 | HIGH | 7.8 | 0.3% | Nov 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOBs when building SMB2_IOCTL requ... |
| CVE-2024-50150 | HIGH | 7.8 | 0.2% | Nov 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmode should keep reference to parent... |
| CVE-2024-50143 | HIGH | 7.8 | 0.3% | Nov 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: udf: fix uninit-value use in udf_get_fileshortad C... |
| CVE-2024-10203 | HIGH | 7.8 | 0.3% | Nov 7, 2024 | Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrar... |
| CVE-2024-38286 | HIGH | 7.5 | 1.7% | Nov 7, 2024 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: ... |
| CVE-2024-10947 | HIGH | 7.2 | 0.5% | Nov 7, 2024 | A vulnerability classified as critical was found in Guangzhou Tuchuang Computer Software Development Interlib Library Cl... |
| CVE-2024-10946 | HIGH | 7.2 | 0.5% | Nov 7, 2024 | A vulnerability classified as critical has been found in Guangzhou Tuchuang Computer Software Development Interlib Libra... |
| CVE-2024-48325 | HIGH | 8.1 | 0.9% | Nov 6, 2024 | Portabilis i-Educar 2.8.0 is vulnerable to SQL Injection in the "getDocuments" function of the "InstituicaoDocumentacaoC... |
| CVE-2024-50340 | HIGH | 7.3 | 63.4% | Nov 6, 2024 | symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. ... |
| CVE-2024-20536 | HIGH | 8.8 | 0.8% | Nov 6, 2024 | A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (ND... |
| CVE-2024-20528 | HIGH | 7.2 | 0.6% | Nov 6, 2024 | A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload files to arbitrary locat... |
| CVE-2024-20484 | HIGH | 7.5 | 0.6% | Nov 6, 2024 | A vulnerability in the External Agent Assignment Service (EAAS) feature of Cisco Enterprise Chat and Email (ECE) could a... |
| CVE-2024-10827 | HIGH | 8.8 | 0.6% | Nov 6, 2024 | Use after free in Serial in Google Chrome prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap ... |
| CVE-2024-10826 | HIGH | 8.8 | 0.6% | Nov 6, 2024 | Use after free in Family Experiences in Google Chrome on Android prior to 130.0.6723.116 allowed a remote attacker to po... |
| CVE-2024-6861 | HIGH | 7.5 | 0.7% | Nov 6, 2024 | A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is ena... |
| CVE-2024-8614 | HIGH | 8.8 | 0.8% | Nov 6, 2024 | The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2024-9946 | HIGH | 8.1 | 0.6% | Nov 6, 2024 | The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authe... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now