2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-48951HIGH7.5An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoin...
CVE-2024-48950HIGH7.5An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing u...
CVE-2024-40715HIGH7.7A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform ...
CVE-2024-10963HIGH7.4A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This ...
CVE-2024-10668HIGH7.5There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root...
CVE-2024-43440HIGH7.5A flaw was found in moodle. A local file may include risks when restoring block backups.
CVE-2024-43438HIGH7.5A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients ...
CVE-2024-43436HIGH7.2A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.
CVE-2024-43434HIGH8.1The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check,...
CVE-2024-43431HIGH7.5A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does n...
CVE-2024-43428HIGH7.1To address a cache poisoning risk in Moodle, additional validation for local storage was required.
CVE-2024-43426HIGH7.5A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk o...
CVE-2024-43425HIGH8.1A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated que...
CVE-2024-24914HIGH8Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix t...
CVE-2024-10526HIGH8.6Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation ...
CVE-2024-50164HIGH7.1In the Linux kernel, the following vulnerability has been resolved: bpf: Fix overloading of MEM_UNINIT's meaning Lonia...
CVE-2024-50159HIGH7.8In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix the double free in scmi_deb...
CVE-2024-50158HIGH7.8In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix out of bound check Driver export...
CVE-2024-50155HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netdevsim: use cond_resched() in nsim_dev_trap_repo...
CVE-2024-50154HIGH7In the Linux kernel, the following vulnerability has been resolved: tcp/dccp: Don't use timer_pending() in reqsk_queue_...
CVE-2024-50151HIGH7.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOBs when building SMB2_IOCTL requ...
CVE-2024-50150HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmode should keep reference to parent...
CVE-2024-50143HIGH7.8In the Linux kernel, the following vulnerability has been resolved: udf: fix uninit-value use in udf_get_fileshortad C...
CVE-2024-10203HIGH7.8Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrar...
CVE-2024-38286HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now