2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50841 | MEDIUM | 5.4 | 0.4% | Nov 14, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/calendar_of_events.php in KASHIPARA E-learning Man... |
| CVE-2024-50840 | MEDIUM | 5.4 | 0.4% | Nov 14, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/class.php in KASHIPARA E-learning Management Syste... |
| CVE-2024-50839 | MEDIUM | 5.4 | 0.4% | Nov 14, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management... |
| CVE-2024-11215 | MEDIUM | 6.5 | 0.7% | Nov 14, 2024 | Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web ser... |
| CVE-2024-8648 | MEDIUM | 6.1 | 0.4% | Nov 14, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 ... |
| CVE-2024-7404 | MEDIUM | 6.5 | 0.5% | Nov 14, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 pr... |
| CVE-2024-11207 | MEDIUM | 5.4 | 0.3% | Nov 14, 2024 | A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unk... |
| CVE-2024-10978 | MEDIUM | 4.2 | 0.7% | Nov 14, 2024 | Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows ... |
| CVE-2024-10976 | MEDIUM | 5.4 | 0.8% | Nov 14, 2024 | Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows fro... |
| CVE-2024-45642 | MEDIUM | 5.3 | 0.5% | Nov 14, 2024 | IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arb... |
| CVE-2024-45099 | MEDIUM | 4.8 | 0.2% | Nov 14, 2024 | IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arb... |
| CVE-2024-3447 | MEDIUM | 6 | 0.6% | Nov 14, 2024 | A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_co... |
| CVE-2024-8180 | MEDIUM | 5.4 | 0.4% | Nov 14, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.... |
| CVE-2024-5920 | MEDIUM | 4.8 | 0.3% | Nov 14, 2024 | A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Pan... |
| CVE-2024-5919 | MEDIUM | 6.5 | 0.3% | Nov 14, 2024 | A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authent... |
| CVE-2024-5918 | MEDIUM | 4.3 | 0.2% | Nov 14, 2024 | An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a... |
| CVE-2024-5917 | MEDIUM | 4.9 | 0.5% | Nov 14, 2024 | A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use... |
| CVE-2024-47914 | MEDIUM | 4.5 | 0.2% | Nov 14, 2024 | VaeMendis - CWE-352: Cross-Site Request Forgery (CSRF) |
| CVE-2024-2552 | MEDIUM | 6 | 0.5% | Nov 14, 2024 | A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass... |
| CVE-2024-7787 | MEDIUM | 5.1 | 0.4% | Nov 14, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ITG Compute... |
| CVE-2024-10146 | MEDIUM | 5.4 | 0.6% | Nov 14, 2024 | The Simple File List WordPress plugin before 6.1.13 does not sanitise and escape a generated URL before outputting it ba... |
| CVE-2024-5083 | MEDIUM | 5.1 | 0.4% | Nov 14, 2024 | A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2 This issue affects Nexus... |
| CVE-2024-40410 | MEDIUM | 4.8 | 0.1% | Nov 13, 2024 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for ... |
| CVE-2024-51027 | MEDIUM | 6.5 | 6.8% | Nov 13, 2024 | Ruijie NBR800G gateway NBR_RGOS_11.1(6)B4P9 is vulnerable to command execution in /itbox_pi/networksafe.php via the prov... |
| CVE-2024-50956 | MEDIUM | 6.5 | 0.3% | Nov 13, 2024 | A buffer overflow in the RecvSocketData function of Inovance HCPLC_AM401-CPU1608TPTN 21.38.0.0, HCPLC_AM402-CPU1608TPTN ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now