2024 CVE Vulnerabilities
39,220 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10315 | MEDIUM | 6.9 | 0.3% | Nov 11, 2024 | In Gliffy Online an insecure configuration was discovered in versions before 4.14.0-6. Reported by Alpha Inferno PVT LTD... |
| CVE-2024-45087 | MEDIUM | 4.8 | 0.2% | Nov 11, 2024 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileg... |
| CVE-2024-10917 | MEDIUM | 5.3 | 0.4% | Nov 11, 2024 | In Eclipse OpenJ9 versions up to 0.47, the JNI function GetStringUTFLength may return an incorrect value which has wrapp... |
| CVE-2024-45088 | MEDIUM | 5.4 | 0.2% | Nov 11, 2024 | IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows authenticate... |
| CVE-2024-43439 | MEDIUM | 6.1 | 0.4% | Nov 11, 2024 | A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting... |
| CVE-2024-51054 | MEDIUM | 4.8 | 0.4% | Nov 11, 2024 | A Cross Site Scriptng (XSS) vulnerability was found in /omrs/admin/search.php in PHPGurukul Online Marriage Registration... |
| CVE-2024-50991 | MEDIUM | 4.8 | 0.4% | Nov 11, 2024 | A Cross Site Scripting (XSS) vulnerability was found in /ums-sp/admin/registered-users.php in PHPGurukul User Management... |
| CVE-2024-50990 | MEDIUM | 6.1 | 0.4% | Nov 11, 2024 | A Reflected Cross Site Scriptng (XSS) vulnerability was found in /omrs/user/search.php in PHPGurukul Online Marriage Reg... |
| CVE-2024-11070 | MEDIUM | 5.4 | 0.4% | Nov 11, 2024 | A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS 5.202406.d. This issue affects... |
| CVE-2024-50263 | MEDIUM | 5.5 | 0.2% | Nov 11, 2024 | In the Linux kernel, the following vulnerability has been resolved: fork: only invoke khugepaged, ksm hooks if no error... |
| CVE-2024-34014 | MEDIUM | 5.5 | 0.2% | Nov 11, 2024 | Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Ac... |
| CVE-2024-43437 | MEDIUM | 6.1 | 0.3% | Nov 11, 2024 | A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scrip... |
| CVE-2024-43435 | MEDIUM | 5.3 | 0.3% | Nov 11, 2024 | A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries ... |
| CVE-2024-43433 | MEDIUM | 5.3 | 0.3% | Nov 11, 2024 | A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Mo... |
| CVE-2024-43432 | MEDIUM | 5.3 | 0.3% | Nov 11, 2024 | A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, bu... |
| CVE-2024-43430 | MEDIUM | 5.3 | 0.3% | Nov 11, 2024 | A flaw was found in moodle. External API access to Quiz can override contained insufficient access control. |
| CVE-2024-43429 | MEDIUM | 5.3 | 0.3% | Nov 11, 2024 | A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in user... |
| CVE-2024-11021 | MEDIUM | 5.4 | 0.3% | Nov 11, 2024 | Webopac from Grand Vice info has Stored Cross-site Scripting vulnerability. Remote attackers with regular privileges can... |
| CVE-2024-52355 | MEDIUM | 5.4 | 0.3% | Nov 11, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MiKa OSM osm.This ... |
| CVE-2024-52354 | MEDIUM | 5.4 | 0.3% | Nov 11, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cool Plugins Web S... |
| CVE-2024-52353 | MEDIUM | 5.4 | 0.2% | Nov 11, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gabriel Serafini C... |
| CVE-2024-52352 | MEDIUM | 5.4 | 0.2% | Nov 11, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in miloandrew Postcas... |
| CVE-2024-52351 | MEDIUM | 5.4 | 0.2% | Nov 11, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BU Web Team BU Sli... |
| CVE-2024-52350 | MEDIUM | 5.4 | 0.2% | Nov 11, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nrmendez CRM 2go c... |
| CVE-2024-11019 | MEDIUM | 6.1 | 0.3% | Nov 11, 2024 | Webopac from Grand Vice info has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attacke... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now