2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-48901MEDIUM4.3A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a re...
CVE-2024-48898MEDIUM4.3A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from othe...
CVE-2024-48897MEDIUM4.3A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds th...
CVE-2024-48896MEDIUM4.3A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' na...
CVE-2024-11319MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS ...
CVE-2024-11023MEDIUM6.1Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncU...
CVE-2024-42391MEDIUM5.3Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex...
CVE-2024-42390MEDIUM5.3Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex...
CVE-2024-42389MEDIUM5.3Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex...
CVE-2024-42388MEDIUM5.3Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex...
CVE-2024-42387MEDIUM5.3Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex...
CVE-2024-41972MEDIUM6.5A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file r...
CVE-2024-41970MEDIUM5.7A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for...
CVE-2024-41968MEDIUM5.4A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.
CVE-2024-52947MEDIUM5.4A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary we...
CVE-2024-52944MEDIUM5.4An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated rem...
CVE-2024-52943MEDIUM5.4An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated rem...
CVE-2024-52942MEDIUM5.4An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated rem...
CVE-2024-52941MEDIUM5.4An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated rem...
CVE-2024-11308MEDIUM5.5The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore th...
CVE-2024-52926MEDIUM6.5Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.
CVE-2024-52922MEDIUM6.5In Bitcoin Core before 25.1, an attacker can cause a node to not download the latest block, because there can be minutes...
CVE-2024-52921MEDIUM5.3In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block.
CVE-2024-52919MEDIUM6.5Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via ...
CVE-2024-52918MEDIUM6.5Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and ap...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now