2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52899 | HIGH | 8.8 | 0.8% | Nov 26, 2024 | IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL para... |
| CVE-2024-11676 | MEDIUM | 5.4 | 0.5% | Nov 26, 2024 | A vulnerability was found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this is... |
| CVE-2024-11675 | MEDIUM | 5.4 | 0.5% | Nov 26, 2024 | A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by th... |
| CVE-2024-53843 | HIGH | 8.1 | 0.5% | Nov 26, 2024 | @dapperduckling/keycloak-connector-server is an opinionated series of libraries for Node.js applications and frontend cl... |
| CVE-2024-11674 | HIGH | 8.8 | 0.6% | Nov 26, 2024 | A vulnerability, which was classified as critical, was found in CodeAstro Hospital Management System 1.0. Affected is an... |
| CVE-2024-11673 | MEDIUM | 4.3 | 0.3% | Nov 25, 2024 | A vulnerability, which was classified as problematic, has been found in 1000 Projects Bookstore Management System 1.0. T... |
| CVE-2024-53597 | MEDIUM | 6.3 | 0.3% | Nov 25, 2024 | masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit. |
| CVE-2024-53554 | HIGH | 8 | 0.7% | Nov 25, 2024 | A Client-Side Template Injection (CSTI) vulnerability in the component /project/new/scrum of Taiga v 8.6.1 allows remote... |
| CVE-2024-53102 | — | — | — | Nov 25, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-53101 | MEDIUM | 5.5 | 0.2% | Nov 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: fs: Fix uninitialized value issue in from_kuid and ... |
| CVE-2024-53100 | MEDIUM | 4.7 | 0.2% | Nov 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: nvme: tcp: avoid race between queue_lock lock and d... |
| CVE-2024-53099 | HIGH | 7.1 | 0.2% | Nov 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: Check validity of link->type in bpf_link_show_... |
| CVE-2024-53098 | HIGH | 7.8 | 0.2% | Nov 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/ufence: Prefetch ufence addr to catch bogus ... |
| CVE-2024-53097 | MEDIUM | 5.5 | 0.2% | Nov 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: mm: krealloc: Fix MTE false alarm in __do_krealloc ... |
| CVE-2024-53096 | HIGH | 7.8 | 0.3% | Nov 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: mm: resolve faulty mmap_region() error path behavio... |
| CVE-2024-53556 | MEDIUM | 6.1 | 0.3% | Nov 25, 2024 | An Open Redirect vulnerability in Taiga v6.8.1 allows attackers to redirect users to arbitrary websites via appending a ... |
| CVE-2024-50672 | CRITICAL | 9.8 | 1.5% | Nov 25, 2024 | A NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to res... |
| CVE-2024-50671 | MEDIUM | 4.3 | 0.3% | Nov 25, 2024 | Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles... |
| CVE-2024-53268 | HIGH | 8.8 | 0.7% | Nov 25, 2024 | Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and ... |
| CVE-2024-53262 | MEDIUM | 5.4 | 0.5% | Nov 25, 2024 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. The static error.html ... |
| CVE-2024-53261 | MEDIUM | 5.4 | 0.3% | Nov 25, 2024 | SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. "Unsanitized input fro... |
| CVE-2024-53258 | MEDIUM | 5.3 | 0.5% | Nov 25, 2024 | Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 o... |
| CVE-2024-53599 | MEDIUM | 5.4 | 0.3% | Nov 25, 2024 | A cross-site scripting (XSS) vulnerability in the /scroll.php endpoint of LafeLabs Chaos v0.0.1 allows attackers to exec... |
| CVE-2024-53255 | MEDIUM | 5.4 | 0.9% | Nov 25, 2024 | BoidCMS is a free and open-source flat file CMS for building simple websites and blogs, developed using PHP and uses JSO... |
| CVE-2024-52811 | HIGH | 8.2 | 0.8% | Nov 25, 2024 | The ngtcp2 project is an effort to implement IETF QUIC protocol in C. In affected versions acks are not validated before... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now