2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47586 | MEDIUM | 5.3 | 3.6% | Nov 12, 2024 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously cra... |
| CVE-2024-42372 | MEDIUM | 6.5 | 0.3% | Nov 12, 2024 | Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read a... |
| CVE-2024-11096 | MEDIUM | 6.5 | 0.5% | Nov 12, 2024 | A vulnerability, which was classified as critical, was found in code-projects Task Manager 1.0. This affects an unknown ... |
| CVE-2024-11079 | MEDIUM | 5.5 | 0.5% | Nov 12, 2024 | A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hos... |
| CVE-2024-51213 | MEDIUM | 6.1 | 0.3% | Nov 11, 2024 | Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the... |
| CVE-2024-50601 | MEDIUM | 6.1 | 0.2% | Nov 11, 2024 | Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to ve... |
| CVE-2024-23983 | MEDIUM | 5.8 | 0.4% | Nov 11, 2024 | Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules. |
| CVE-2024-51026 | MEDIUM | 5.4 | 0.3% | Nov 11, 2024 | The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endp... |
| CVE-2024-52531 | MEDIUM | 6.5 | 0.7% | Nov 11, 2024 | GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_pars... |
| CVE-2024-52288 | MEDIUM | 5.1 | 0.1% | Nov 11, 2024 | libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with supp... |
| CVE-2024-51992 | MEDIUM | 4.1 | 0.3% | Nov 11, 2024 | Orchid is a @laravel package that allows for rapid application development of back-office applications, admin/user panel... |
| CVE-2024-51489 | MEDIUM | 5.4 | 0.3% | Nov 11, 2024 | Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing d... |
| CVE-2024-51488 | MEDIUM | 5.4 | 0.3% | Nov 11, 2024 | Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing d... |
| CVE-2024-51190 | MEDIUM | 4.8 | 0.4% | Nov 11, 2024 | TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)... |
| CVE-2024-51189 | MEDIUM | 4.8 | 0.4% | Nov 11, 2024 | TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)... |
| CVE-2024-51188 | MEDIUM | 4.8 | 0.4% | Nov 11, 2024 | TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)... |
| CVE-2024-51187 | MEDIUM | 4.8 | 0.4% | Nov 11, 2024 | TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)... |
| CVE-2024-46965 | MEDIUM | 5.4 | 0.2% | Nov 11, 2024 | The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows a... |
| CVE-2024-11078 | MEDIUM | 5.4 | 0.4% | Nov 11, 2024 | A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. Affected by this vuln... |
| CVE-2024-10315 | MEDIUM | 6.9 | 0.3% | Nov 11, 2024 | In Gliffy Online an insecure configuration was discovered in versions before 4.14.0-6. Reported by Alpha Inferno PVT LTD... |
| CVE-2024-45087 | MEDIUM | 4.8 | 0.2% | Nov 11, 2024 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileg... |
| CVE-2024-10917 | MEDIUM | 5.3 | 0.4% | Nov 11, 2024 | In Eclipse OpenJ9 versions up to 0.47, the JNI function GetStringUTFLength may return an incorrect value which has wrapp... |
| CVE-2024-45088 | MEDIUM | 5.4 | 0.2% | Nov 11, 2024 | IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows authenticate... |
| CVE-2024-43439 | MEDIUM | 6.1 | 0.4% | Nov 11, 2024 | A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting... |
| CVE-2024-51054 | MEDIUM | 4.8 | 0.4% | Nov 11, 2024 | A Cross Site Scriptng (XSS) vulnerability was found in /omrs/admin/search.php in PHPGurukul Online Marriage Registration... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now