2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21853 | MEDIUM | 5.7 | 0.2% | Nov 13, 2024 | Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors m... |
| CVE-2024-21808 | MEDIUM | 4.2 | 0.2% | Nov 13, 2024 | Improper buffer restrictions in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to pote... |
| CVE-2024-21783 | MEDIUM | 4.8 | 0.2% | Nov 13, 2024 | Integer overflow for some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially ena... |
| CVE-2024-11193 | MEDIUM | 6.5 | 0.3% | Nov 13, 2024 | An information disclosure vulnerability exists in Yugabyte Anywhere, where the LDAP bind password is logged in plaintext... |
| CVE-2024-42834 | MEDIUM | 5.4 | 0.5% | Nov 13, 2024 | A stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC... |
| CVE-2024-40443 | MEDIUM | 4.3 | 0.7% | Nov 13, 2024 | SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to... |
| CVE-2024-49379 | MEDIUM | 5.3 | 1.2% | Nov 13, 2024 | Umbrel is a home server OS for self-hosting. The login functionality of Umbrel before version 1.2.2 contains a reflected... |
| CVE-2024-43090 | MEDIUM | 5 | 0.2% | Nov 13, 2024 | In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to l... |
| CVE-2024-43086 | MEDIUM | 5.5 | 0.1% | Nov 13, 2024 | In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a thir... |
| CVE-2024-43084 | MEDIUM | 5.5 | 0.1% | Nov 13, 2024 | In visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to ... |
| CVE-2024-43083 | MEDIUM | 5.5 | 0.1% | Nov 13, 2024 | In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to resource exhaustion.... |
| CVE-2024-43082 | MEDIUM | 5.5 | 0.1% | Nov 13, 2024 | In onActivityResult of EditUserPhotoController.java, there is a possible cross-user media read due to a confused deputy.... |
| CVE-2024-9476 | MEDIUM | 5.1 | 0.2% | Nov 13, 2024 | A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to re... |
| CVE-2024-52292 | MEDIUM | 6.5 | 0.7% | Nov 13, 2024 | Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions o... |
| CVE-2024-45594 | MEDIUM | 5.4 | 0.2% | Nov 13, 2024 | Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subj... |
| CVE-2024-8049 | MEDIUM | 6.5 | 0.4% | Nov 13, 2024 | In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with un... |
| CVE-2024-7295 | MEDIUM | 6.2 | 0.1% | Nov 13, 2024 | In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an... |
| CVE-2024-52305 | MEDIUM | 4.8 | 0.2% | Nov 13, 2024 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exi... |
| CVE-2024-50969 | MEDIUM | 6.1 | 0.5% | Nov 13, 2024 | A Reflected cross-site scripting (XSS) vulnerability in browse.php of Code-projects Jonnys Liquor 1.0 allows remote atta... |
| CVE-2024-11175 | MEDIUM | 4.8 | 0.5% | Nov 13, 2024 | A vulnerability was found in Public CMS 5.202406.d and classified as problematic. This issue affects some unknown proces... |
| CVE-2024-9477 | MEDIUM | 6.1 | 0.2% | Nov 13, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AirTies Air... |
| CVE-2024-49505 | MEDIUM | 6.1 | 0.3% | Nov 13, 2024 | A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumblew... |
| CVE-2024-48900 | MEDIUM | 4.3 | 0.3% | Nov 13, 2024 | A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipi... |
| CVE-2024-11165 | MEDIUM | 5.7 | 0.1% | Nov 13, 2024 | An information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in ... |
| CVE-2024-11159 | MEDIUM | 4.3 | 0.3% | Nov 13, 2024 | Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects T... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now