2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49379 | MEDIUM | 5.3 | 1.2% | Nov 13, 2024 | Umbrel is a home server OS for self-hosting. The login functionality of Umbrel before version 1.2.2 contains a reflected... |
| CVE-2024-43090 | MEDIUM | 5 | 0.2% | Nov 13, 2024 | In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to l... |
| CVE-2024-43086 | MEDIUM | 5.5 | 0.1% | Nov 13, 2024 | In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a thir... |
| CVE-2024-43084 | MEDIUM | 5.5 | 0.1% | Nov 13, 2024 | In visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to ... |
| CVE-2024-43083 | MEDIUM | 5.5 | 0.1% | Nov 13, 2024 | In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to resource exhaustion.... |
| CVE-2024-43082 | MEDIUM | 5.5 | 0.1% | Nov 13, 2024 | In onActivityResult of EditUserPhotoController.java, there is a possible cross-user media read due to a confused deputy.... |
| CVE-2024-9476 | MEDIUM | 5.1 | 0.2% | Nov 13, 2024 | A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to re... |
| CVE-2024-52292 | MEDIUM | 6.5 | 0.7% | Nov 13, 2024 | Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions o... |
| CVE-2024-45594 | MEDIUM | 5.4 | 0.2% | Nov 13, 2024 | Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subj... |
| CVE-2024-8049 | MEDIUM | 6.5 | 0.4% | Nov 13, 2024 | In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with un... |
| CVE-2024-7295 | MEDIUM | 6.2 | 0.1% | Nov 13, 2024 | In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an... |
| CVE-2024-52305 | MEDIUM | 4.8 | 0.2% | Nov 13, 2024 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exi... |
| CVE-2024-50969 | MEDIUM | 6.1 | 0.5% | Nov 13, 2024 | A Reflected cross-site scripting (XSS) vulnerability in browse.php of Code-projects Jonnys Liquor 1.0 allows remote atta... |
| CVE-2024-11175 | MEDIUM | 4.8 | 0.5% | Nov 13, 2024 | A vulnerability was found in Public CMS 5.202406.d and classified as problematic. This issue affects some unknown proces... |
| CVE-2024-9477 | MEDIUM | 6.1 | 0.2% | Nov 13, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AirTies Air... |
| CVE-2024-49505 | MEDIUM | 6.1 | 0.3% | Nov 13, 2024 | A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumblew... |
| CVE-2024-48900 | MEDIUM | 4.3 | 0.3% | Nov 13, 2024 | A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipi... |
| CVE-2024-11165 | MEDIUM | 5.7 | 0.1% | Nov 13, 2024 | An information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in ... |
| CVE-2024-11159 | MEDIUM | 4.3 | 0.3% | Nov 13, 2024 | Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects T... |
| CVE-2024-8001 | MEDIUM | 4.3 | 0.7% | Nov 13, 2024 | A vulnerability was found in VIWIS LMS 9.11. It has been classified as critical. Affected is an unknown function of the ... |
| CVE-2024-9682 | MEDIUM | 5.4 | 0.4% | Nov 13, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-9668 | MEDIUM | 5.4 | 0.4% | Nov 13, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-9059 | MEDIUM | 5.4 | 0.4% | Nov 13, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Googl... |
| CVE-2024-10877 | MEDIUM | 6.1 | 0.6% | Nov 13, 2024 | The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the... |
| CVE-2024-52268 | MEDIUM | 4.8 | 0.3% | Nov 13, 2024 | Cross-site scripting vulnerability exists in VK All in One Expansion Unit versions prior to 9.100.1.0. If this vulnerabi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now