2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11145 | CRITICAL | 9.8 | 1.0% | Nov 26, 2024 | Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker t... |
| CVE-2024-10240 | MEDIUM | 5.3 | 0.5% | Nov 26, 2024 | An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting... |
| CVE-2024-8237 | HIGH | 7.5 | 0.6% | Nov 26, 2024 | A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 12.6 prior to 17.4.5... |
| CVE-2024-8177 | HIGH | 7.5 | 0.6% | Nov 26, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 pr... |
| CVE-2024-8114 | HIGH | 8.8 | 0.7% | Nov 26, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.... |
| CVE-2024-53844 | MEDIUM | 6.3 | 0.4% | Nov 26, 2024 | E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. A path traversal vulnerab... |
| CVE-2024-53620 | MEDIUM | 4.8 | 0.4% | Nov 26, 2024 | A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execut... |
| CVE-2024-53619 | MEDIUM | 6.3 | 0.5% | Nov 26, 2024 | An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute ... |
| CVE-2024-53267 | MEDIUM | 5.5 | 0.1% | Nov 26, 2024 | sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient ver... |
| CVE-2024-52008 | HIGH | 8.8 | 0.5% | Nov 26, 2024 | Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password... |
| CVE-2024-32965 | HIGH | 8.6 | 23.7% | Nov 26, 2024 | Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnera... |
| CVE-2024-11828 | HIGH | 7.5 | 0.6% | Nov 26, 2024 | A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17.... |
| CVE-2024-11669 | HIGH | 7.5 | 0.5% | Nov 26, 2024 | An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 b... |
| CVE-2024-11668 | MEDIUM | 5.3 | 0.3% | Nov 26, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17... |
| CVE-2024-51058 | MEDIUM | 6.2 | 0.8% | Nov 26, 2024 | Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read a... |
| CVE-2024-10878 | MEDIUM | 6.1 | 0.4% | Nov 26, 2024 | The Sugar Calendar – Simple Event Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to... |
| CVE-2024-53555 | HIGH | 8.8 | 0.7% | Nov 26, 2024 | A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV fil... |
| CVE-2024-53365 | MEDIUM | 5.4 | 0.4% | Nov 26, 2024 | A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 i... |
| CVE-2024-11407 | HIGH | 7.5 | 0.6% | Nov 26, 2024 | There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled ... |
| CVE-2024-11177 | — | — | — | Nov 26, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-52337 | MEDIUM | 5.5 | 0.3% | Nov 26, 2024 | A log spoofing flaw was found in the Tuned package due to improper sanitization of some API arguments. This flaw allows ... |
| CVE-2024-52336 | HIGH | 7.8 | 0.3% | Nov 26, 2024 | A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be call... |
| CVE-2024-36463 | HIGH | 8.8 | 0.8% | Nov 26, 2024 | The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal... |
| CVE-2024-22117 | LOW | 2.2 | 0.5% | Nov 26, 2024 | When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the s... |
| CVE-2024-9929 | MEDIUM | 4.3 | 0.3% | Nov 26, 2024 | A vulnerability exists in NSD570 that allows any authenticated user to access all device logs disclosing login informati... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now