2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52056 | MEDIUM | 6.5 | 0.7% | Nov 21, 2024 | Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any... |
| CVE-2024-52055 | MEDIUM | 4.9 | 1.0% | Nov 21, 2024 | Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any f... |
| CVE-2024-52616 | MEDIUM | 5.3 | 0.7% | Nov 21, 2024 | A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementi... |
| CVE-2024-52615 | MEDIUM | 5.3 | 0.6% | Nov 21, 2024 | A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies at... |
| CVE-2024-49588 | MEDIUM | 6.8 | 0.3% | Nov 21, 2024 | Multiple endpoints in `oracle-sidecar` in versions 0.347.0 to 0.543.0 were found to be vulnerable to SQL injections. |
| CVE-2024-53094 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Add sendpage_ok() check to disable MSG_SP... |
| CVE-2024-53093 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: defer partition scanning We need t... |
| CVE-2024-53092 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: virtio_pci: Fix admin vq cleanup by using correct i... |
| CVE-2024-53091 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: Add sk_is_inet and IS_ICSK check in tls_sw_has... |
| CVE-2024-53090 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: afs: Fix lock recursion afs_wake_up_async_call() c... |
| CVE-2024-53089 | MEDIUM | 5.5 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Mark hrtimer to expire in hard inte... |
| CVE-2024-53333 | MEDIUM | 6.3 | 17.5% | Nov 21, 2024 | TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. Th... |
| CVE-2024-52309 | MEDIUM | 5.1 | 0.6% | Nov 21, 2024 | SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azur... |
| CVE-2024-52307 | MEDIUM | 5.6 | 0.5% | Nov 21, 2024 | authentik is an open-source identity provider. Due to the usage of a non-constant time comparison for the /-/metrics/ en... |
| CVE-2024-49529 | MEDIUM | 5.5 | 0.3% | Nov 21, 2024 | InDesign Desktop versions 19.0, 20.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to ... |
| CVE-2024-45517 | MEDIUM | 5.4 | 0.5% | Nov 21, 2024 | An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h... |
| CVE-2024-45513 | MEDIUM | 4.8 | 0.4% | Nov 21, 2024 | An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A stored Cross-Site Scripting (XSS) vulnerability ex... |
| CVE-2024-45194 | MEDIUM | 4.8 | 0.5% | Nov 21, 2024 | In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability in the Webmail Modern UI allows execution of stored Cross-Si... |
| CVE-2024-8526 | MEDIUM | 5.9 | 0.6% | Nov 21, 2024 | A vulnerability in Automated Logic WebCTRL 7.0 could allow an attacker to send a maliciously crafted URL, which when vis... |
| CVE-2024-45514 | MEDIUM | 5.4 | 0.6% | Nov 21, 2024 | An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists i... |
| CVE-2024-45512 | MEDIUM | 5.4 | 0.4% | Nov 21, 2024 | An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerabilit... |
| CVE-2024-48747 | MEDIUM | 6.8 | 0.9% | Nov 21, 2024 | An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file. |
| CVE-2024-7130 | MEDIUM | 5.5 | 0.4% | Nov 21, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kion Comput... |
| CVE-2024-53426 | MEDIUM | 6.2 | 0.3% | Nov 21, 2024 | A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function. |
| CVE-2024-53425 | MEDIUM | 6.2 | 0.3% | Nov 21, 2024 | A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue oc... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now