2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48951 | HIGH | 7.5 | 0.3% | Nov 7, 2024 | An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoin... |
| CVE-2024-48950 | HIGH | 7.5 | 0.3% | Nov 7, 2024 | An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing u... |
| CVE-2024-40715 | HIGH | 7.7 | 0.6% | Nov 7, 2024 | A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform ... |
| CVE-2024-10963 | HIGH | 7.4 | 0.8% | Nov 7, 2024 | A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This ... |
| CVE-2024-10668 | HIGH | 7.5 | 0.4% | Nov 7, 2024 | There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root... |
| CVE-2024-43440 | HIGH | 7.5 | 0.6% | Nov 7, 2024 | A flaw was found in moodle. A local file may include risks when restoring block backups. |
| CVE-2024-43438 | HIGH | 7.5 | 0.5% | Nov 7, 2024 | A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients ... |
| CVE-2024-43436 | HIGH | 7.2 | 0.6% | Nov 7, 2024 | A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators. |
| CVE-2024-43434 | HIGH | 8.1 | 0.6% | Nov 7, 2024 | The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check,... |
| CVE-2024-43431 | HIGH | 7.5 | 0.5% | Nov 7, 2024 | A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does n... |
| CVE-2024-43428 | HIGH | 7.1 | 0.2% | Nov 7, 2024 | To address a cache poisoning risk in Moodle, additional validation for local storage was required. |
| CVE-2024-43426 | HIGH | 7.5 | 0.6% | Nov 7, 2024 | A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk o... |
| CVE-2024-43425 | HIGH | 8.1 | 83.3% | Nov 7, 2024 | A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated que... |
| CVE-2024-24914 | HIGH | 8 | 0.4% | Nov 7, 2024 | Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix t... |
| CVE-2024-10526 | HIGH | 8.6 | 0.2% | Nov 7, 2024 | Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation ... |
| CVE-2024-50164 | HIGH | 7.1 | 0.2% | Nov 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix overloading of MEM_UNINIT's meaning Lonia... |
| CVE-2024-50159 | HIGH | 7.8 | 0.2% | Nov 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix the double free in scmi_deb... |
| CVE-2024-50158 | HIGH | 7.8 | 0.2% | Nov 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix out of bound check Driver export... |
| CVE-2024-50155 | HIGH | 7.8 | 0.2% | Nov 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: netdevsim: use cond_resched() in nsim_dev_trap_repo... |
| CVE-2024-50154 | HIGH | 7 | 0.2% | Nov 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: tcp/dccp: Don't use timer_pending() in reqsk_queue_... |
| CVE-2024-50151 | HIGH | 7.8 | 0.3% | Nov 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOBs when building SMB2_IOCTL requ... |
| CVE-2024-50150 | HIGH | 7.8 | 0.2% | Nov 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmode should keep reference to parent... |
| CVE-2024-50143 | HIGH | 7.8 | 0.3% | Nov 7, 2024 | In the Linux kernel, the following vulnerability has been resolved: udf: fix uninit-value use in udf_get_fileshortad C... |
| CVE-2024-10203 | HIGH | 7.8 | 0.3% | Nov 7, 2024 | Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrar... |
| CVE-2024-38286 | HIGH | 7.5 | 1.7% | Nov 7, 2024 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now