2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34891 | MEDIUM | 6.8 | 0.3% | Nov 4, 2024 | Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrator... |
| CVE-2024-34885 | MEDIUM | 6.8 | 0.4% | Nov 4, 2024 | Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrato... |
| CVE-2024-30618 | MEDIUM | 6.1 | 0.4% | Nov 4, 2024 | A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary J... |
| CVE-2024-30617 | MEDIUM | 5.4 | 0.2% | Nov 4, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to in... |
| CVE-2024-10768 | MEDIUM | 5.4 | 0.4% | Nov 4, 2024 | A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects... |
| CVE-2024-51328 | MEDIUM | 6.1 | 0.4% | Nov 4, 2024 | Cross Site Scripting vulnerability in addcategory.php in projectworld's Travel Management System v1.0 allows remote atta... |
| CVE-2024-34887 | MEDIUM | 4.9 | 0.3% | Nov 4, 2024 | Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administr... |
| CVE-2024-34883 | MEDIUM | 4.9 | 0.4% | Nov 4, 2024 | Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators... |
| CVE-2024-34882 | MEDIUM | 4.9 | 0.3% | Nov 4, 2024 | Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrato... |
| CVE-2024-51685 | MEDIUM | 4.8 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gan... |
| CVE-2024-51683 | MEDIUM | 5.4 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Custom pos... |
| CVE-2024-51682 | MEDIUM | 5.4 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HasThemes HT Build... |
| CVE-2024-51681 | MEDIUM | 5.4 | 0.3% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeRevolution WP ... |
| CVE-2024-51680 | MEDIUM | 5.4 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrestaProject Cres... |
| CVE-2024-51678 | MEDIUM | 5.4 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcel Pol Elo Rat... |
| CVE-2024-51677 | MEDIUM | 5.4 | 0.2% | Nov 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Knowledge Bas... |
| CVE-2024-51665 | MEDIUM | 4.3 | 0.5% | Nov 4, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor ... |
| CVE-2024-51408 | MEDIUM | 6.5 | 0.5% | Nov 4, 2024 | AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to ... |
| CVE-2024-9147 | MEDIUM | 6.1 | 0.2% | Nov 4, 2024 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik... |
| CVE-2024-51560 | MEDIUM | 4.3 | 0.3% | Nov 4, 2024 | This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint.... |
| CVE-2024-51559 | MEDIUM | 6.5 | 0.3% | Nov 4, 2024 | This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticate... |
| CVE-2024-51557 | MEDIUM | 6.5 | 0.4% | Nov 4, 2024 | This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authentica... |
| CVE-2024-51556 | MEDIUM | 6.5 | 0.2% | Nov 4, 2024 | This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response.... |
| CVE-2024-10523 | MEDIUM | 4.6 | 0.1% | Nov 4, 2024 | This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device f... |
| CVE-2024-38405 | MEDIUM | 6.5 | 0.2% | Nov 4, 2024 | Transient DOS while processing the CU information from RNR IE. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now