2024 CVE Vulnerabilities
39,220 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8881 | MEDIUM | 6.8 | 0.7% | Nov 12, 2024 | A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version ... |
| CVE-2024-49393 | MEDIUM | 6.5 | 0.3% | Nov 12, 2024 | In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker tha... |
| CVE-2024-11097 | MEDIUM | 5.5 | 0.3% | Nov 12, 2024 | A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as problematic. Thi... |
| CVE-2024-47593 | MEDIUM | 4.3 | 0.4% | Nov 12, 2024 | SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the serv... |
| CVE-2024-47592 | MEDIUM | 5.3 | 0.3% | Nov 12, 2024 | SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the... |
| CVE-2024-47588 | MEDIUM | 4.7 | 0.1% | Nov 12, 2024 | In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors,... |
| CVE-2024-47586 | MEDIUM | 5.3 | 3.6% | Nov 12, 2024 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously cra... |
| CVE-2024-42372 | MEDIUM | 6.5 | 0.3% | Nov 12, 2024 | Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read a... |
| CVE-2024-11096 | MEDIUM | 6.5 | 0.5% | Nov 12, 2024 | A vulnerability, which was classified as critical, was found in code-projects Task Manager 1.0. This affects an unknown ... |
| CVE-2024-11079 | MEDIUM | 5.5 | 0.5% | Nov 12, 2024 | A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hos... |
| CVE-2024-51213 | MEDIUM | 6.1 | 0.3% | Nov 11, 2024 | Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the... |
| CVE-2024-50601 | MEDIUM | 6.1 | 0.2% | Nov 11, 2024 | Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to ve... |
| CVE-2024-23983 | MEDIUM | 5.8 | 0.4% | Nov 11, 2024 | Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules. |
| CVE-2024-51026 | MEDIUM | 5.4 | 0.3% | Nov 11, 2024 | The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endp... |
| CVE-2024-52531 | MEDIUM | 6.5 | 0.7% | Nov 11, 2024 | GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_pars... |
| CVE-2024-52288 | MEDIUM | 5.1 | 0.1% | Nov 11, 2024 | libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with supp... |
| CVE-2024-51992 | MEDIUM | 4.1 | 0.3% | Nov 11, 2024 | Orchid is a @laravel package that allows for rapid application development of back-office applications, admin/user panel... |
| CVE-2024-51489 | MEDIUM | 5.4 | 0.3% | Nov 11, 2024 | Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing d... |
| CVE-2024-51488 | MEDIUM | 5.4 | 0.3% | Nov 11, 2024 | Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing d... |
| CVE-2024-51190 | MEDIUM | 4.8 | 0.4% | Nov 11, 2024 | TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)... |
| CVE-2024-51189 | MEDIUM | 4.8 | 0.4% | Nov 11, 2024 | TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)... |
| CVE-2024-51188 | MEDIUM | 4.8 | 0.4% | Nov 11, 2024 | TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)... |
| CVE-2024-51187 | MEDIUM | 4.8 | 0.4% | Nov 11, 2024 | TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)... |
| CVE-2024-46965 | MEDIUM | 5.4 | 0.2% | Nov 11, 2024 | The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows a... |
| CVE-2024-11078 | MEDIUM | 5.4 | 0.4% | Nov 11, 2024 | A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. Affected by this vuln... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now