2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52001 | MEDIUM | 4.3 | 0.3% | Nov 8, 2024 | Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access for... |
| CVE-2024-52000 | MEDIUM | 6.1 | 0.4% | Nov 8, 2024 | Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site ... |
| CVE-2024-35427 | MEDIUM | 5.5 | 0.2% | Nov 8, 2024 | vmir e8117 was discovered to contain a segmentation violation via the export_function function at /src/vmir_wasm_parser.... |
| CVE-2024-35425 | MEDIUM | 5.5 | 0.2% | Nov 8, 2024 | vmir e8117 was discovered to contain a segmentation violation via the function_prepare_parse function at /src/vmir_funct... |
| CVE-2024-35424 | MEDIUM | 5.5 | 0.2% | Nov 8, 2024 | vmir e8117 was discovered to contain a segmentation violation via the import_function function at /src/vmir_wasm_parser.... |
| CVE-2024-35421 | MEDIUM | 5.5 | 0.2% | Nov 8, 2024 | vmir e8117 was discovered to contain a segmentation violation via the wasm_parse_block function at /src/vmir_wasm_parser... |
| CVE-2024-35420 | MEDIUM | 6.2 | 0.2% | Nov 8, 2024 | wac commit 385e1 was discovered to contain a heap overflow. |
| CVE-2024-35419 | MEDIUM | 5.5 | 0.2% | Nov 8, 2024 | wac commit 385e1 was discovered to contain a heap overflow via the load_module function at /wac-asan/wa.c. This vulnerab... |
| CVE-2024-35418 | MEDIUM | 6.2 | 0.2% | Nov 8, 2024 | wac commit 385e1 was discovered to contain a heap overflow via the setup_call function at /wac-asan/wa.c. This vulnerabi... |
| CVE-2024-35410 | MEDIUM | 6.2 | 0.3% | Nov 8, 2024 | wac commit 385e1 was discovered to contain a heap overflow via the interpret function at /wac-asan/wa.c. This vulnerabil... |
| CVE-2024-51157 | MEDIUM | 4.7 | 0.2% | Nov 8, 2024 | 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component http://erp.07fly.net:80/... |
| CVE-2024-21994 | MEDIUM | 4.3 | 0.3% | Nov 8, 2024 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9 are susceptible to a Denial of Service (DoS) vulnerab... |
| CVE-2024-51055 | MEDIUM | 6.5 | 0.6% | Nov 8, 2024 | An issue Hoosk v1.7.1 allows a remote attacker to execute arbitrary code via a crafted script to the config.php componen... |
| CVE-2024-50810 | MEDIUM | 5.4 | 0.2% | Nov 8, 2024 | hopetree izone lts c011b48 contains a Cross Site Scripting (XSS) vulnerability in the article comment function. In \apps... |
| CVE-2024-44765 | MEDIUM | 6.5 | 0.7% | Nov 8, 2024 | An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4... |
| CVE-2024-9841 | MEDIUM | 6.1 | 0.2% | Nov 8, 2024 | A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcS... |
| CVE-2024-51032 | MEDIUM | 5.4 | 0.4% | Nov 8, 2024 | A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allo... |
| CVE-2024-51031 | MEDIUM | 5.4 | 0.4% | Nov 8, 2024 | A Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management System 1.0 allows remo... |
| CVE-2024-51030 | MEDIUM | 6.5 | 0.7% | Nov 8, 2024 | A SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management System 1.0 allows r... |
| CVE-2024-40240 | MEDIUM | 6.8 | 0.3% | Nov 8, 2024 | An incorrect access control issue in HomeServe Home Repair' android app - 3.3.4 allows a physically proximate attacker t... |
| CVE-2024-40239 | MEDIUM | 6.8 | 0.3% | Nov 8, 2024 | An incorrect access control issue in Life: Personal Diary, Journal android app 17.5.0 allows a physically proximate atta... |
| CVE-2024-46948 | MEDIUM | 4.3 | 0.3% | Nov 8, 2024 | Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control. |
| CVE-2024-46947 | MEDIUM | 6.5 | 0.4% | Nov 8, 2024 | Northern.tech Mender before 3.6.6 and 3.7.x before 3.7.7 allows SSRF. |
| CVE-2024-50378 | MEDIUM | 4.9 | 1.2% | Nov 8, 2024 | Airflow versions before 2.10.3 have a vulnerability that allows authenticated users with audit log access to see sensiti... |
| CVE-2024-10325 | MEDIUM | 5.4 | 0.3% | Nov 8, 2024 | The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now