2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51679 | MEDIUM | 6.1 | 0.2% | Nov 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in gentlesource Appointmind appointmind allows Stored XSS.This issue aff... |
| CVE-2024-51156 | MEDIUM | 4.7 | 0.2% | Nov 14, 2024 | 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp.07fly.net:80/admin/... |
| CVE-2024-40579 | MEDIUM | 5.4 | 0.3% | Nov 14, 2024 | Cross Site Scripting vulnerability in Virtuozzo Hybrid Server for WHMCS Open Source v.1.7.1 allows a remote attacker to ... |
| CVE-2024-39707 | MEDIUM | 5.3 | 0.2% | Nov 14, 2024 | Insyde IHISI function 0x49 can restore factory defaults for certain UEFI variables without further authentication by def... |
| CVE-2024-49025 | MEDIUM | 4.3 | 0.5% | Nov 14, 2024 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2024-10396 | MEDIUM | 6.5 | 0.5% | Nov 14, 2024 | An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, pos... |
| CVE-2024-52524 | MEDIUM | 6.9 | 0.8% | Nov 14, 2024 | Giskard is an evaluation and testing framework for AI systems. A Remote Code Execution (ReDoS) vulnerability was discove... |
| CVE-2024-4311 | MEDIUM | 5.4 | 0.5% | Nov 14, 2024 | zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password chan... |
| CVE-2024-48284 | MEDIUM | 4.8 | 0.5% | Nov 14, 2024 | A Reflected Cross-Site Scripting (XSS) vulnerability was found in the /search-result.php page of the PHPGurukul User Reg... |
| CVE-2024-1682 | MEDIUM | 4.3 | 0.4% | Nov 14, 2024 | An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This ... |
| CVE-2024-50836 | MEDIUM | 4.8 | 0.5% | Nov 14, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/teachers.php in KASHIPARA E-learning Management Sy... |
| CVE-2024-52505 | MEDIUM | 5.4 | 0.4% | Nov 14, 2024 | matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of the matrix-apps... |
| CVE-2024-42188 | MEDIUM | 4.6 | 0.2% | Nov 14, 2024 | HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update dat... |
| CVE-2024-7124 | MEDIUM | 5.3 | 1.0% | Nov 14, 2024 | Improper Neutralization of Input During Web Page Generation vulnerability in DInGO dLibra software in the parameter 'fil... |
| CVE-2024-50838 | MEDIUM | 5.4 | 0.5% | Nov 14, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/department.php in KASHIPARA E-learning Management ... |
| CVE-2024-50837 | MEDIUM | 5.4 | 0.5% | Nov 14, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/admin_user.php in KASHIPARA E-learning Management ... |
| CVE-2024-11210 | MEDIUM | 5.4 | 0.6% | Nov 14, 2024 | A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of th... |
| CVE-2024-50843 | MEDIUM | 5.3 | 0.6% | Nov 14, 2024 | A Directory listing issue was found in PHPGurukul User Registration & Login and User Management System 3.2, which allows... |
| CVE-2024-50842 | MEDIUM | 5.4 | 0.4% | Nov 14, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/school_year.php in KASHIPARA E-learning Management... |
| CVE-2024-50841 | MEDIUM | 5.4 | 0.4% | Nov 14, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/calendar_of_events.php in KASHIPARA E-learning Man... |
| CVE-2024-50840 | MEDIUM | 5.4 | 0.4% | Nov 14, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/class.php in KASHIPARA E-learning Management Syste... |
| CVE-2024-50839 | MEDIUM | 5.4 | 0.4% | Nov 14, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management... |
| CVE-2024-11215 | MEDIUM | 6.5 | 0.7% | Nov 14, 2024 | Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web ser... |
| CVE-2024-8648 | MEDIUM | 6.1 | 0.4% | Nov 14, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 ... |
| CVE-2024-7404 | MEDIUM | 6.5 | 0.5% | Nov 14, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 pr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now