2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47193 | MEDIUM | 5.5 | 0.2% | Nov 29, 2024 | WithSecure Elements Agent for Mac before 24.3, MDR before 24.3, and Elements Client Security for Mac before 16.10 allow ... |
| CVE-2024-36626 | MEDIUM | 5.3 | 0.6% | Nov 29, 2024 | In prestashop 8.1.4, a NULL pointer dereference was identified in the math_round function within Tools.php. |
| CVE-2024-36625 | MEDIUM | 5.4 | 0.4% | Nov 29, 2024 | Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the replace_emoji_with_text function in ui_util.ts. |
| CVE-2024-36619 | MEDIUM | 5.3 | 0.7% | Nov 29, 2024 | FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow w... |
| CVE-2024-35369 | MEDIUM | 5.5 | 0.2% | Nov 29, 2024 | In FFmpeg version n6.1.1, specifically within the avcodec/speexdec.c module, a potential security vulnerability exists d... |
| CVE-2024-52782 | CRITICAL | 9.8 | 0.7% | Nov 29, 2024 | DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code... |
| CVE-2024-52781 | CRITICAL | 9.8 | 0.7% | Nov 29, 2024 | DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code... |
| CVE-2024-52780 | CRITICAL | 9.8 | 0.7% | Nov 29, 2024 | DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code... |
| CVE-2024-52779 | CRITICAL | 9.8 | 0.7% | Nov 29, 2024 | DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code... |
| CVE-2024-52778 | CRITICAL | 9.8 | 0.7% | Nov 29, 2024 | DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code... |
| CVE-2024-52777 | CRITICAL | 9.8 | 0.7% | Nov 29, 2024 | DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L, <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Cod... |
| CVE-2024-48406 | CRITICAL | 9.8 | 0.9% | Nov 29, 2024 | Buffer Overflow vulnerability in SunBK201 umicat through v.0.3.2 and fixed in v.0.3.3 allows an attacker to execute arbi... |
| CVE-2024-36671 | CRITICAL | 9.8 | 0.7% | Nov 29, 2024 | nodemcu before v3.0.0-release_20240225 was discovered to contain an integer overflow via the getnum function at /modules... |
| CVE-2024-11992 | CRITICAL | 9.1 | 0.8% | Nov 29, 2024 | Absolute path traversal vulnerability in Quick.CMS, version 6.7, the exploitation of which could allow remote users to b... |
| CVE-2024-11990 | MEDIUM | 4.6 | 0.3% | Nov 29, 2024 | A Cross-Site Scripting (XSS) vulnerability in SurgeMail v78c2 could allow an attacker to execute arbitrary JavaScript co... |
| CVE-2024-50357 | CRITICAL | 9.8 | 0.6% | Nov 29, 2024 | FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in t... |
| CVE-2024-47094 | MEDIUM | 5.5 | 0.2% | Nov 29, 2024 | Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL... |
| CVE-2024-9044 | MEDIUM | 4.6 | 0.2% | Nov 29, 2024 | A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across mu... |
| CVE-2024-11983 | HIGH | 7.2 | 1.1% | Nov 29, 2024 | Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers wit... |
| CVE-2024-11982 | HIGH | 7.2 | 0.6% | Nov 29, 2024 | Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers wi... |
| CVE-2024-11482 | CRITICAL | 9.8 | 2.5% | Nov 29, 2024 | A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code exe... |
| CVE-2024-11481 | HIGH | 8.2 | 0.4% | Nov 29, 2024 | A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper han... |
| CVE-2024-11014 | MEDIUM | 4.3 | 0.2% | Nov 29, 2024 | Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 u... |
| CVE-2024-11013 | HIGH | 7.2 | 1.1% | Nov 29, 2024 | Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27,... |
| CVE-2024-11981 | HIGH | 7.5 | 0.5% | Nov 29, 2024 | Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated atta... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now