2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53849 | MEDIUM | 4.8 | 0.2% | Nov 27, 2024 | editorconfig-core-c is theEditorConfig core library written in C (for use by plugins supporting EditorConfig parsing).... |
| CVE-2024-43784 | MEDIUM | 5.7 | 0.3% | Nov 26, 2024 | lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have ... |
| CVE-2024-11743 | MEDIUM | 4.3 | 0.3% | Nov 26, 2024 | A vulnerability, which was classified as problematic, was found in SourceCodester Best House Rental Management System 1.... |
| CVE-2024-11742 | MEDIUM | 5.4 | 0.5% | Nov 26, 2024 | A vulnerability, which was classified as problematic, has been found in SourceCodester Best House Rental Management Syst... |
| CVE-2024-10240 | MEDIUM | 5.3 | 0.5% | Nov 26, 2024 | An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting... |
| CVE-2024-53844 | MEDIUM | 6.3 | 0.4% | Nov 26, 2024 | E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. A path traversal vulnerab... |
| CVE-2024-53620 | MEDIUM | 4.8 | 0.4% | Nov 26, 2024 | A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execut... |
| CVE-2024-53619 | MEDIUM | 6.3 | 0.5% | Nov 26, 2024 | An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute ... |
| CVE-2024-53267 | MEDIUM | 5.5 | 0.1% | Nov 26, 2024 | sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient ver... |
| CVE-2024-11668 | MEDIUM | 5.3 | 0.3% | Nov 26, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17... |
| CVE-2024-51058 | MEDIUM | 6.2 | 0.8% | Nov 26, 2024 | Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read a... |
| CVE-2024-10878 | MEDIUM | 6.1 | 0.4% | Nov 26, 2024 | The Sugar Calendar – Simple Event Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to... |
| CVE-2024-53365 | MEDIUM | 5.4 | 0.4% | Nov 26, 2024 | A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 i... |
| CVE-2024-52337 | MEDIUM | 5.5 | 0.3% | Nov 26, 2024 | A log spoofing flaw was found in the Tuned package due to improper sanitization of some API arguments. This flaw allows ... |
| CVE-2024-9929 | MEDIUM | 4.3 | 0.3% | Nov 26, 2024 | A vulnerability exists in NSD570 that allows any authenticated user to access all device logs disclosing login informati... |
| CVE-2024-9928 | MEDIUM | 5.3 | 0.4% | Nov 26, 2024 | A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, thi... |
| CVE-2024-8236 | MEDIUM | 5.4 | 0.4% | Nov 26, 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc... |
| CVE-2024-53976 | MEDIUM | 5.4 | 0.3% | Nov 26, 2024 | Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, maki... |
| CVE-2024-53975 | MEDIUM | 5.4 | 0.3% | Nov 26, 2024 | Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to... |
| CVE-2024-11708 | MEDIUM | 6.5 | 0.3% | Nov 26, 2024 | Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This... |
| CVE-2024-11706 | MEDIUM | 6.5 | 0.5% | Nov 26, 2024 | A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Ut... |
| CVE-2024-11703 | MEDIUM | 5.7 | 0.2% | Nov 26, 2024 | On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authenticatio... |
| CVE-2024-11701 | MEDIUM | 4.3 | 0.4% | Nov 26, 2024 | The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could hav... |
| CVE-2024-11696 | MEDIUM | 5.4 | 0.3% | Nov 26, 2024 | The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature ver... |
| CVE-2024-11695 | MEDIUM | 5.4 | 0.4% | Nov 26, 2024 | A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resultin... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now