2024 CVE Vulnerabilities
39,220 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10611 | HIGH | 8.8 | 0.5% | Nov 1, 2024 | A vulnerability was found in ESAFENET CDG 5 and classified as critical. This issue affects the function delProtocol of t... |
| CVE-2024-10610 | HIGH | 8.8 | 0.5% | Nov 1, 2024 | A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function del... |
| CVE-2024-10599 | HIGH | 7.5 | 0.9% | Oct 31, 2024 | A vulnerability, which was classified as problematic, has been found in Tongda OA 2017 up to 11.7. This issue affects so... |
| CVE-2024-10596 | HIGH | 8.8 | 0.5% | Oct 31, 2024 | A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function delEn... |
| CVE-2024-10594 | HIGH | 8.8 | 0.5% | Oct 31, 2024 | A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function docHistory of ... |
| CVE-2024-48360 | HIGH | 7.5 | 3.9% | Oct 31, 2024 | Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.p... |
| CVE-2024-39722 | HIGH | 7.5 | 3.9% | Oct 31, 2024 | An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via ... |
| CVE-2024-39721 | HIGH | 7.5 | 2.7% | Oct 31, 2024 | An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until compl... |
| CVE-2024-39720 | HIGH | 8.2 | 2.5% | Oct 31, 2024 | An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file c... |
| CVE-2024-39719 | HIGH | 7.5 | 4.1% | Oct 31, 2024 | An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the C... |
| CVE-2024-51066 | HIGH | 7.5 | 0.5% | Oct 31, 2024 | An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Manage... |
| CVE-2024-48200 | HIGH | 8.4 | 0.2% | Oct 31, 2024 | An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove fun... |
| CVE-2024-8185 | HIGH | 7.5 | 0.5% | Oct 31, 2024 | Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a den... |
| CVE-2024-51254 | HIGH | 8.8 | 0.4% | Oct 31, 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm... |
| CVE-2024-49685 | HIGH | 8.8 | 0.2% | Oct 31, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Custom Twitter Feeds (Tweets Widget) custom-twitter-feeds... |
| CVE-2024-43984 | HIGH | 8.8 | 0.3% | Oct 31, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue af... |
| CVE-2024-43383 | HIGH | 8.1 | 1.2% | Oct 31, 2024 | Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's... |
| CVE-2024-21537 | HIGH | 8.9 | 1.1% | Oct 31, 2024 | Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the inse... |
| CVE-2024-48311 | HIGH | 8.8 | 0.3% | Oct 31, 2024 | Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function. |
| CVE-2024-10559 | HIGH | 7.8 | 0.4% | Oct 31, 2024 | A vulnerability was found in SourceCodester Airport Booking Management System 1.0 and classified as critical. Affected b... |
| CVE-2024-51426 | HIGH | 8.8 | 0.5% | Oct 30, 2024 | An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an... |
| CVE-2024-51425 | HIGH | 8.8 | 0.4% | Oct 30, 2024 | An issue in the WaterToken smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have ... |
| CVE-2024-51243 | HIGH | 7.2 | 0.9% | Oct 30, 2024 | The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deploy... |
| CVE-2024-48735 | HIGH | 7.7 | 1.0% | Oct 30, 2024 | Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote ... |
| CVE-2024-48734 | HIGH | 8.8 | 0.6% | Oct 30, 2024 | Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote atta... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now