2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36618 | MEDIUM | 6.2 | 0.2% | Nov 29, 2024 | FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, po... |
| CVE-2024-36617 | MEDIUM | 6.2 | 0.2% | Nov 29, 2024 | FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder. |
| CVE-2024-47193 | MEDIUM | 5.5 | 0.2% | Nov 29, 2024 | WithSecure Elements Agent for Mac before 24.3, MDR before 24.3, and Elements Client Security for Mac before 16.10 allow ... |
| CVE-2024-36626 | MEDIUM | 5.3 | 0.6% | Nov 29, 2024 | In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php. |
| CVE-2024-36625 | MEDIUM | 5.4 | 0.4% | Nov 29, 2024 | Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts. |
| CVE-2024-36619 | MEDIUM | 5.3 | 0.7% | Nov 29, 2024 | FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow w... |
| CVE-2024-35369 | MEDIUM | 5.5 | 0.2% | Nov 29, 2024 | In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists d... |
| CVE-2024-11990 | MEDIUM | 4.6 | 0.3% | Nov 29, 2024 | A Cross-Site Scripting (XSS) vulnerability in SurgeMail v78c2 could allow an attacker to execute arbitrary JavaScript co... |
| CVE-2024-47094 | MEDIUM | 5.5 | 0.2% | Nov 29, 2024 | Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL... |
| CVE-2024-9044 | MEDIUM | 4.6 | 0.2% | Nov 29, 2024 | A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across mu... |
| CVE-2024-11014 | MEDIUM | 4.3 | 0.2% | Nov 29, 2024 | Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 u... |
| CVE-2024-39162 | MEDIUM | 6.1 | 0.4% | Nov 29, 2024 | pyspider through 0.3.10 allows /update XSS. NOTE: This vulnerability only affects products that are no longer supported ... |
| CVE-2024-10980 | MEDIUM | 5.4 | 0.3% | Nov 29, 2024 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) WordPress ... |
| CVE-2024-10704 | MEDIUM | 4.8 | 0.4% | Nov 29, 2024 | The Photo Gallery by 10Web WordPress plugin before 1.8.31 does not sanitise and escape some of its settings, which coul... |
| CVE-2024-45495 | MEDIUM | 4.3 | 0.2% | Nov 29, 2024 | MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking. |
| CVE-2024-35451 | MEDIUM | 4.8 | 0.3% | Nov 29, 2024 | LinkStack 2.7.9 through 4.7.7 allows resources\views\components\favicon.blade.php link SSRF. |
| CVE-2024-54123 | MEDIUM | 6.1 | 0.3% | Nov 29, 2024 | Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text... |
| CVE-2024-11971 | MEDIUM | 5.4 | 0.5% | Nov 28, 2024 | A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerab... |
| CVE-2024-7747 | MEDIUM | 6.5 | 0.5% | Nov 28, 2024 | The Wallet for WooCommerce plugin for WordPress is vulnerable to incorrect conversion between numeric types in all versi... |
| CVE-2024-53731 | MEDIUM | 6.5 | 0.3% | Nov 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fintelligence Fint... |
| CVE-2024-8308 | MEDIUM | 6.5 | 0.6% | Nov 28, 2024 | A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP requ... |
| CVE-2024-53737 | MEDIUM | 5.4 | 0.3% | Nov 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandtoss WP Mails... |
| CVE-2024-52283 | MEDIUM | 5.7 | 0.3% | Nov 28, 2024 | Missing sanitation of inputs allowed arbitrary users to conduct a stored XSS attack that triggers for users that view a ... |
| CVE-2024-49503 | MEDIUM | 4.6 | 0.3% | Nov 28, 2024 | A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SUSE mana... |
| CVE-2024-49502 | MEDIUM | 4.6 | 0.3% | Nov 28, 2024 | A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now