2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37423 | HIGH | 8.5 | 0.4% | Nov 1, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic Newspack Bloc... |
| CVE-2024-37232 | HIGH | 8.8 | 0.4% | Nov 1, 2024 | Missing Authorization vulnerability in Hercules Design Hercules Core allows Exploiting Incorrectly Configured Access Con... |
| CVE-2024-37108 | HIGH | 7.7 | 0.6% | Nov 1, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WishList Products WishLi... |
| CVE-2024-37106 | HIGH | 8.2 | 0.3% | Nov 1, 2024 | Missing Authorization vulnerability in WishList Products WishList Member X allows Exploiting Incorrectly Configured Acce... |
| CVE-2024-27524 | HIGH | 7.1 | 0.7% | Nov 1, 2024 | Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafte... |
| CVE-2024-48270 | HIGH | 7.5 | 0.5% | Nov 1, 2024 | An issue in the component /logins of oasys v1.1 allows attackers to access sensitive information via a burst attack. |
| CVE-2024-10653 | HIGH | 7.2 | 0.6% | Nov 1, 2024 | IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator inter... |
| CVE-2024-0106 | HIGH | 8.7 | 0.2% | Nov 1, 2024 | NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker ma... |
| CVE-2024-0105 | HIGH | 8.9 | 0.3% | Nov 1, 2024 | NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privi... |
| CVE-2024-47939 | HIGH | 7.7 | 0.7% | Nov 1, 2024 | Stack-based buffer overflow vulnerability exists in multiple laser printers and MFPs which implement Ricoh Web Image Mon... |
| CVE-2024-10613 | HIGH | 8.8 | 0.5% | Nov 1, 2024 | A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the fun... |
| CVE-2024-10612 | HIGH | 8.8 | 0.5% | Nov 1, 2024 | A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function removeHookInva... |
| CVE-2024-10611 | HIGH | 8.8 | 0.5% | Nov 1, 2024 | A vulnerability was found in ESAFENET CDG 5 and classified as critical. This issue affects the function delProtocol of t... |
| CVE-2024-10610 | HIGH | 8.8 | 0.5% | Nov 1, 2024 | A vulnerability has been found in ESAFENET CDG 5 and classified as critical. This vulnerability affects the function del... |
| CVE-2024-10599 | HIGH | 7.5 | 0.9% | Oct 31, 2024 | A vulnerability, which was classified as problematic, has been found in Tongda OA 2017 up to 11.7. This issue affects so... |
| CVE-2024-10596 | HIGH | 8.8 | 0.5% | Oct 31, 2024 | A vulnerability was found in ESAFENET CDG 5. It has been rated as critical. Affected by this issue is the function delEn... |
| CVE-2024-10594 | HIGH | 8.8 | 0.5% | Oct 31, 2024 | A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. Affected is the function docHistory of ... |
| CVE-2024-48360 | HIGH | 7.5 | 3.9% | Oct 31, 2024 | Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.p... |
| CVE-2024-39722 | HIGH | 7.5 | 3.9% | Oct 31, 2024 | An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via ... |
| CVE-2024-39721 | HIGH | 7.5 | 2.7% | Oct 31, 2024 | An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until compl... |
| CVE-2024-39720 | HIGH | 8.2 | 2.5% | Oct 31, 2024 | An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file c... |
| CVE-2024-39719 | HIGH | 7.5 | 4.1% | Oct 31, 2024 | An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the C... |
| CVE-2024-51066 | HIGH | 7.5 | 0.5% | Oct 31, 2024 | An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Manage... |
| CVE-2024-48200 | HIGH | 8.4 | 0.2% | Oct 31, 2024 | An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove fun... |
| CVE-2024-8185 | HIGH | 7.5 | 0.5% | Oct 31, 2024 | Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a den... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now