2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53979 | HIGH | 8.2 | 0.1% | Nov 29, 2024 | ibm.ibm_zhmc is an Ansible collection for the IBM Z HMC. The Ansible collection "ibm.ibm_zhmc" writes password-like prop... |
| CVE-2024-53865 | HIGH | 8.2 | 0.1% | Nov 29, 2024 | zhmcclient is a pure Python client library for the IBM Z HMC Web Services API. In affected versions the Python package "... |
| CVE-2024-53864 | MEDIUM | 5.3 | 0.5% | Nov 29, 2024 | Ibexa Admin UI Bundle is all the necessary parts to run the Ibexa DXP Back Office interface. The Content name pattern is... |
| CVE-2024-53861 | HIGH | 7.5 | 0.8% | Nov 29, 2024 | pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting ... |
| CVE-2024-53848 | HIGH | 7.1 | 0.1% | Nov 29, 2024 | check-jsonschema is a CLI and set of pre-commit hooks for jsonschema validation. The default cache strategy uses the bas... |
| CVE-2024-52810 | MEDIUM | 6.9 | 0.7% | Nov 29, 2024 | @intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerabl... |
| CVE-2024-52809 | MEDIUM | 5.3 | 0.6% | Nov 29, 2024 | vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `... |
| CVE-2024-52801 | MEDIUM | 5.3 | 0.4% | Nov 29, 2024 | sftpgo is a full-featured and highly configurable event-driven file transfer solution. Server protocols: SFTP, HTTP/S, F... |
| CVE-2024-52800 | LOW | 2.3 | 1.1% | Nov 29, 2024 | veraPDF is an open source PDF/A validation library. Executing policy checks using custom schematron files via the CLI in... |
| CVE-2024-52003 | MEDIUM | 6.1 | 0.4% | Nov 29, 2024 | Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows... |
| CVE-2024-36616 | MEDIUM | 6.5 | 0.6% | Nov 29, 2024 | An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of ... |
| CVE-2024-36615 | MEDIUM | 5.9 | 0.4% | Nov 29, 2024 | FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding para... |
| CVE-2024-36611 | HIGH | 7.5 | 0.8% | Nov 29, 2024 | In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to ad... |
| CVE-2024-49360 | HIGH | 8.4 | 0.5% | Nov 29, 2024 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. An authenticat... |
| CVE-2024-36624 | MEDIUM | 5.4 | 0.4% | Nov 29, 2024 | Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js. |
| CVE-2024-36623 | HIGH | 8.1 | 0.6% | Nov 29, 2024 | moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger mult... |
| CVE-2024-36622 | CRITICAL | 9.8 | 2.8% | Nov 29, 2024 | In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vuln... |
| CVE-2024-36621 | MEDIUM | 6.5 | 0.6% | Nov 29, 2024 | moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could... |
| CVE-2024-36620 | MEDIUM | 6.5 | 0.8% | Nov 29, 2024 | moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go. |
| CVE-2024-36618 | MEDIUM | 6.2 | 0.2% | Nov 29, 2024 | FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, po... |
| CVE-2024-36617 | MEDIUM | 6.2 | 0.2% | Nov 29, 2024 | FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder. |
| CVE-2024-49806 | CRITICAL | 9.8 | 0.3% | Nov 29, 2024 | IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryp... |
| CVE-2024-49805 | CRITICAL | 9.8 | 0.3% | Nov 29, 2024 | IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryp... |
| CVE-2024-49804 | HIGH | 7.8 | 0.2% | Nov 29, 2024 | IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non-administrative user... |
| CVE-2024-49803 | HIGH | 8.8 | 0.8% | Nov 29, 2024 | IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now