2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11789 | HIGH | 7.8 | 0.3% | Nov 28, 2024 | Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vul... |
| CVE-2024-11787 | HIGH | 7.8 | 0.3% | Nov 28, 2024 | Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vul... |
| CVE-2024-53860 | HIGH | 8.6 | 0.5% | Nov 27, 2024 | sp-php-email-handler is a PHP package for handling contact form submissions. Messages sent using this script are vulnera... |
| CVE-2024-53859 | HIGH | 7.5 | 0.5% | Nov 27, 2024 | go-gh is a Go module for interacting with the `gh` utility and the GitHub API from the command line. A security vulnerab... |
| CVE-2024-53858 | MEDIUM | 6.5 | 0.3% | Nov 27, 2024 | The gh cli is GitHub’s official command line tool. A security vulnerability has been identified in the GitHub CLI that c... |
| CVE-2024-53260 | MEDIUM | 6.8 | 0.5% | Nov 27, 2024 | Autolab is a course management service that enables auto-graded programming assignments. A user can modify their first a... |
| CVE-2024-53855 | MEDIUM | 4.3 | 0.4% | Nov 27, 2024 | Centurion ERP (Enterprise Rescource Planning) is a simple application developed to provide open source IT management wit... |
| CVE-2024-53264 | MEDIUM | 5.1 | 0.8% | Nov 27, 2024 | bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). A open redirect vulnerability exists in ... |
| CVE-2024-47181 | HIGH | 7.5 | 0.6% | Nov 27, 2024 | Contiki-NG is an open-source, cross-platform operating system for IoT devices. An unaligned memory access can be trigger... |
| CVE-2024-41126 | CRITICAL | 9.6 | 0.3% | Nov 27, 2024 | Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be tr... |
| CVE-2024-41125 | CRITICAL | 9.6 | 0.3% | Nov 27, 2024 | Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be tr... |
| CVE-2024-9369 | CRITICAL | 9.6 | 0.6% | Nov 27, 2024 | Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromis... |
| CVE-2024-7025 | HIGH | 8.8 | 0.6% | Nov 27, 2024 | Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap... |
| CVE-2024-53254 | — | — | — | Nov 27, 2024 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2024-11160 | — | — | — | Nov 27, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2024-54004 | MEDIUM | 4.3 | 0.8% | Nov 27, 2024 | Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects ... |
| CVE-2024-54003 | HIGH | 8 | 77.5% | Nov 27, 2024 | Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting ... |
| CVE-2024-51228 | MEDIUM | 6.8 | 3.8% | Nov 27, 2024 | An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300R... |
| CVE-2024-37816 | MEDIUM | 4.2 | 0.2% | Nov 27, 2024 | Quectel EC25-EUX EC25EUXGAR08A05M1G was discovered to contain a stack overflow. |
| CVE-2024-31976 | HIGH | 8 | 1.0% | Nov 27, 2024 | EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controll... |
| CVE-2024-21703 | MEDIUM | 6.4 | 0.2% | Nov 27, 2024 | This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center a... |
| CVE-2024-11860 | MEDIUM | 6.5 | 0.8% | Nov 27, 2024 | A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This af... |
| CVE-2024-53920 | HIGH | 7.8 | 0.5% | Nov 27, 2024 | In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) ... |
| CVE-2024-52951 | HIGH | 8 | 1.1% | Nov 27, 2024 | Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authent... |
| CVE-2024-46055 | MEDIUM | 4.8 | 0.4% | Nov 27, 2024 | OpenVidReview 1.0 is vulnerable to Cross Site Scripting (XSS) in review names. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now