2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11225 | MEDIUM | 6.1 | 0.5% | Nov 22, 2024 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Reflected Cross-Site Scripti... |
| CVE-2024-10666 | MEDIUM | 4.3 | 0.4% | Nov 22, 2024 | The Easy Twitter Feed – Twitter feeds plugin for WP plugin for WordPress is vulnerable to Information Exposure in all ve... |
| CVE-2024-10034 | MEDIUM | 5.5 | 0.4% | Nov 22, 2024 | The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native ga... |
| CVE-2024-38296 | MEDIUM | 4.4 | 0.2% | Nov 22, 2024 | Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain ... |
| CVE-2024-47142 | MEDIUM | 5.5 | 0.3% | Nov 22, 2024 | AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue wi... |
| CVE-2024-45837 | MEDIUM | 5.4 | 0.3% | Nov 22, 2024 | Use of hard-coded cryptographic key issue exists in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software. A networ... |
| CVE-2024-39290 | MEDIUM | 6.5 | 0.4% | Nov 22, 2024 | Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticate... |
| CVE-2024-52056 | MEDIUM | 6.5 | 0.7% | Nov 21, 2024 | Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any... |
| CVE-2024-52055 | MEDIUM | 4.9 | 1.0% | Nov 21, 2024 | Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any f... |
| CVE-2024-52616 | MEDIUM | 5.3 | 0.7% | Nov 21, 2024 | A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementi... |
| CVE-2024-52615 | MEDIUM | 5.3 | 0.6% | Nov 21, 2024 | A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies at... |
| CVE-2024-49588 | MEDIUM | 6.8 | 0.3% | Nov 21, 2024 | Multiple endpoints in `oracle-sidecar` in versions 0.347.0 to 0.543.0 were found to be vulnerable to SQL injections. |
| CVE-2024-53094 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Add sendpage_ok() check to disable MSG_SP... |
| CVE-2024-53093 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: defer partition scanning We need t... |
| CVE-2024-53092 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: virtio_pci: Fix admin vq cleanup by using correct i... |
| CVE-2024-53091 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: Add sk_is_inet and IS_ICSK check in tls_sw_has... |
| CVE-2024-53090 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: afs: Fix lock recursion afs_wake_up_async_call() c... |
| CVE-2024-53089 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Mark hrtimer to expire in hard inte... |
| CVE-2024-53333 | MEDIUM | 6.3 | 17.5% | Nov 21, 2024 | TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. Th... |
| CVE-2024-52309 | MEDIUM | 5.1 | 0.6% | Nov 21, 2024 | SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azur... |
| CVE-2024-52307 | MEDIUM | 5.6 | 0.5% | Nov 21, 2024 | authentik is an open-source identity provider. Due to the usage of a non-constant time comparison for the /-/metrics/ en... |
| CVE-2024-49529 | MEDIUM | 5.5 | 0.3% | Nov 21, 2024 | InDesign Desktop versions 19.0, 20.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to ... |
| CVE-2024-45517 | MEDIUM | 5.4 | 0.5% | Nov 21, 2024 | An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h... |
| CVE-2024-45513 | MEDIUM | 4.8 | 0.4% | Nov 21, 2024 | An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A stored Cross-Site Scripting (XSS) vulnerability ex... |
| CVE-2024-45194 | MEDIUM | 4.8 | 0.5% | Nov 21, 2024 | In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability in the Webmail Modern UI allows execution of stored Cross-Si... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now