2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53262 | MEDIUM | 5.4 | 0.5% | Nov 25, 2024 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. The static error.html ... |
| CVE-2024-53261 | MEDIUM | 5.4 | 0.3% | Nov 25, 2024 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. "Unsanitized input fro... |
| CVE-2024-53258 | MEDIUM | 5.3 | 0.5% | Nov 25, 2024 | Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 o... |
| CVE-2024-53599 | MEDIUM | 5.4 | 0.3% | Nov 25, 2024 | A cross-site scripting (XSS) vulnerability in the /scroll.php endpoint of LafeLabs Chaos v0.0.1 allows attackers to exec... |
| CVE-2024-53255 | MEDIUM | 5.4 | 0.9% | Nov 25, 2024 | BoidCMS is a free and open-source flat file CMS for building simple websites and blogs, developed using PHP and uses JSO... |
| CVE-2024-52529 | MEDIUM | 5.8 | 0.5% | Nov 25, 2024 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For users with the following ... |
| CVE-2024-51723 | MEDIUM | 4.6 | 0.3% | Nov 25, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability in the Management Console of BlackBerry AtHoc version 7.15 could allow... |
| CVE-2024-32468 | MEDIUM | 5.4 | 0.3% | Nov 25, 2024 | Deno is a runtime for JavaScript and TypeScript written in rust. Several cross-site scripting vulnerabilities existed in... |
| CVE-2024-11672 | MEDIUM | 4.3 | 0.5% | Nov 25, 2024 | Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on W... |
| CVE-2024-11671 | MEDIUM | 5.4 | 0.5% | Nov 25, 2024 | Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on... |
| CVE-2024-11670 | MEDIUM | 5.4 | 0.6% | Nov 25, 2024 | Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earli... |
| CVE-2024-9666 | MEDIUM | 4.7 | 0.4% | Nov 25, 2024 | A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack ... |
| CVE-2024-11662 | MEDIUM | 6.3 | 0.5% | Nov 25, 2024 | A vulnerability was found in welliamcao OpsManage 3.0.1/3.0.2/3.0.3/3.0.4/3.0.5. It has been rated as critical. This iss... |
| CVE-2024-10451 | MEDIUM | 5.9 | 0.9% | Nov 25, 2024 | A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured dur... |
| CVE-2024-10270 | MEDIUM | 6.5 | 1.3% | Nov 25, 2024 | A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, ... |
| CVE-2024-6538 | MEDIUM | 5.3 | 0.6% | Nov 25, 2024 | A flaw was found in OpenShift Console. A Server Side Request Forgery (SSRF) attack can happen if an attacker supplies al... |
| CVE-2024-11660 | MEDIUM | 5.4 | 0.6% | Nov 25, 2024 | A vulnerability was found in code-projects Farmacia 1.0. It has been classified as problematic. This affects an unknown ... |
| CVE-2024-6393 | MEDIUM | 4.8 | 0.5% | Nov 25, 2024 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.5 does not sanitise and escape some of its Image... |
| CVE-2024-10709 | MEDIUM | 6.8 | 0.7% | Nov 25, 2024 | The YaDisk Files WordPress plugin through 1.2.5 does not validate and escape some of its shortcode attributes before out... |
| CVE-2024-11483 | MEDIUM | 5 | 0.5% | Nov 25, 2024 | A vulnerability was found in the Ansible Automation Platform (AAP). This flaw allows attackers to escalate privileges by... |
| CVE-2024-53930 | MEDIUM | 5.4 | 0.4% | Nov 25, 2024 | WikiDocs before 1.0.65 allows stored XSS by authenticated users via data that comes after $$\\, which is mishandled by a... |
| CVE-2024-53901 | MEDIUM | 5.5 | 0.4% | Nov 24, 2024 | The Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unsp... |
| CVE-2024-35160 | MEDIUM | 6.5 | 0.4% | Nov 23, 2024 | IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2 and IBM Db2 Big SQL on Cloud Pak for Data 7.3, 7.4, 7.5, and 7... |
| CVE-2024-11231 | MEDIUM | 6.4 | 0.4% | Nov 23, 2024 | The 우커머스 네이버페이 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mnp_purchase shortcode... |
| CVE-2024-11229 | MEDIUM | 6.4 | 0.5% | Nov 23, 2024 | The 코드엠샵 소셜톡 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's add_plus_friends and add... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now