2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52422 | MEDIUM | 5.4 | 0.2% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry L. WP Github... |
| CVE-2024-52419 | MEDIUM | 5.4 | 0.2% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Clipboard Agency C... |
| CVE-2024-11304 | MEDIUM | 5.1 | 0.5% | Nov 18, 2024 | Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertec... |
| CVE-2024-9526 | MEDIUM | 5.4 | 0.2% | Nov 18, 2024 | There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipel... |
| CVE-2024-52318 | MEDIUM | 6.1 | 1.7% | Nov 18, 2024 | Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31,... |
| CVE-2024-52317 | MEDIUM | 6.5 | 2.0% | Nov 18, 2024 | Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response u... |
| CVE-2024-48901 | MEDIUM | 4.3 | 0.3% | Nov 18, 2024 | A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a re... |
| CVE-2024-48898 | MEDIUM | 4.3 | 0.3% | Nov 18, 2024 | A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from othe... |
| CVE-2024-48897 | MEDIUM | 4.3 | 0.3% | Nov 18, 2024 | A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds th... |
| CVE-2024-48896 | MEDIUM | 4.3 | 0.4% | Nov 18, 2024 | A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' na... |
| CVE-2024-11319 | MEDIUM | 4.8 | 0.5% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS ... |
| CVE-2024-11023 | MEDIUM | 6.1 | 0.1% | Nov 18, 2024 | Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncU... |
| CVE-2024-42391 | MEDIUM | 5.3 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex... |
| CVE-2024-42390 | MEDIUM | 5.3 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex... |
| CVE-2024-42389 | MEDIUM | 5.3 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex... |
| CVE-2024-42388 | MEDIUM | 5.3 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex... |
| CVE-2024-42387 | MEDIUM | 5.3 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex... |
| CVE-2024-41972 | MEDIUM | 6.5 | 0.6% | Nov 18, 2024 | A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file r... |
| CVE-2024-41970 | MEDIUM | 5.7 | 0.3% | Nov 18, 2024 | A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for... |
| CVE-2024-41968 | MEDIUM | 5.4 | 0.3% | Nov 18, 2024 | A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS. |
| CVE-2024-52947 | MEDIUM | 5.4 | 0.3% | Nov 18, 2024 | A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary we... |
| CVE-2024-52944 | MEDIUM | 5.4 | 0.3% | Nov 18, 2024 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated rem... |
| CVE-2024-52943 | MEDIUM | 5.4 | 1.1% | Nov 18, 2024 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated rem... |
| CVE-2024-52942 | MEDIUM | 5.4 | 0.3% | Nov 18, 2024 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated rem... |
| CVE-2024-52941 | MEDIUM | 5.4 | 0.3% | Nov 18, 2024 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated rem... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now