2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48901 | MEDIUM | 4.3 | 0.3% | Nov 18, 2024 | A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a re... |
| CVE-2024-48898 | MEDIUM | 4.3 | 0.3% | Nov 18, 2024 | A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from othe... |
| CVE-2024-48897 | MEDIUM | 4.3 | 0.3% | Nov 18, 2024 | A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds th... |
| CVE-2024-48896 | MEDIUM | 4.3 | 0.4% | Nov 18, 2024 | A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' na... |
| CVE-2024-11319 | MEDIUM | 4.8 | 0.5% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS ... |
| CVE-2024-11023 | MEDIUM | 6.1 | 0.1% | Nov 18, 2024 | Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncU... |
| CVE-2024-42391 | MEDIUM | 5.3 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex... |
| CVE-2024-42390 | MEDIUM | 5.3 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex... |
| CVE-2024-42389 | MEDIUM | 5.3 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex... |
| CVE-2024-42388 | MEDIUM | 5.3 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex... |
| CVE-2024-42387 | MEDIUM | 5.3 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex... |
| CVE-2024-41972 | MEDIUM | 6.5 | 0.6% | Nov 18, 2024 | A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file r... |
| CVE-2024-41970 | MEDIUM | 5.7 | 0.3% | Nov 18, 2024 | A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for... |
| CVE-2024-41968 | MEDIUM | 5.4 | 0.3% | Nov 18, 2024 | A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS. |
| CVE-2024-52947 | MEDIUM | 5.4 | 0.3% | Nov 18, 2024 | A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary we... |
| CVE-2024-52944 | MEDIUM | 5.4 | 0.3% | Nov 18, 2024 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated rem... |
| CVE-2024-52943 | MEDIUM | 5.4 | 1.1% | Nov 18, 2024 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated rem... |
| CVE-2024-52942 | MEDIUM | 5.4 | 0.3% | Nov 18, 2024 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated rem... |
| CVE-2024-52941 | MEDIUM | 5.4 | 0.3% | Nov 18, 2024 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated rem... |
| CVE-2024-11308 | MEDIUM | 5.5 | 0.2% | Nov 18, 2024 | The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore th... |
| CVE-2024-52926 | MEDIUM | 6.5 | 0.2% | Nov 18, 2024 | Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent. |
| CVE-2024-52922 | MEDIUM | 6.5 | 0.3% | Nov 18, 2024 | In Bitcoin Core before 25.1, an attacker can cause a node to not download the latest block, because there can be minutes... |
| CVE-2024-52921 | MEDIUM | 5.3 | 0.4% | Nov 18, 2024 | In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block. |
| CVE-2024-52919 | MEDIUM | 6.5 | 0.3% | Nov 18, 2024 | Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via ... |
| CVE-2024-52918 | MEDIUM | 6.5 | 0.5% | Nov 18, 2024 | Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and ap... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now