2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48982 | HIGH | 7.5 | 0.5% | Nov 20, 2024 | An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci pac... |
| CVE-2024-48536 | HIGH | 7.5 | 0.5% | Nov 20, 2024 | Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the compa... |
| CVE-2024-48535 | MEDIUM | 5.4 | 0.3% | Nov 20, 2024 | A stored cross-site scripting (XSS) vulnerability in eSoft Planner 3.24.08271-USA allows attackers to execute arbitrary ... |
| CVE-2024-48534 | MEDIUM | 5.4 | 0.4% | Nov 20, 2024 | A reflected cross-site scripting (XSS) vulnerability on the Camp Details module of eSoft Planner 3.24.08271-USA allows a... |
| CVE-2024-48533 | MEDIUM | 5.3 | 0.4% | Nov 20, 2024 | A discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner ... |
| CVE-2024-48531 | MEDIUM | 5.4 | 0.4% | Nov 20, 2024 | A reflected cross-site scripting (XSS) vulnerability on the Rental Availability module of eSoft Planner 3.24.08271-USA a... |
| CVE-2024-48530 | HIGH | 7.5 | 0.6% | Nov 20, 2024 | An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a D... |
| CVE-2024-52757 | MEDIUM | 4.9 | 0.6% | Nov 20, 2024 | D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the notify parameter in the arp_sys_asp funct... |
| CVE-2024-52754 | MEDIUM | 4.9 | 0.6% | Nov 20, 2024 | D-LINK DI-8003 v16.07.16A1 was discovered to contain a buffer overflow via the fn parameter in the tgfile_htm function. |
| CVE-2024-48985 | HIGH | 7.5 | 0.4% | Nov 20, 2024 | An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the len... |
| CVE-2024-48983 | HIGH | 7.5 | 0.4% | Nov 20, 2024 | An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the len... |
| CVE-2024-48981 | HIGH | 7.5 | 0.3% | Nov 20, 2024 | An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the len... |
| CVE-2024-45510 | MEDIUM | 5.4 | 0.3% | Nov 20, 2024 | An issue was discovered in Zimbra Collaboration (ZCS) through 10.0. Zimbra Webmail (Modern UI) is vulnerable to a stored... |
| CVE-2024-45511 | MEDIUM | 5.4 | 0.3% | Nov 20, 2024 | An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A reflected Cross-Site Scripting (XSS) issue exists ... |
| CVE-2024-33439 | CRITICAL | 9.1 | 0.5% | Nov 20, 2024 | An issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary O... |
| CVE-2024-52739 | HIGH | 8 | 9.1% | Nov 20, 2024 | D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_... |
| CVE-2024-29292 | CRITICAL | 9.1 | 1.0% | Nov 20, 2024 | Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated re... |
| CVE-2024-11493 | MEDIUM | 6.1 | 0.4% | Nov 20, 2024 | A vulnerability classified as problematic was found in 115cms up to 20240807. This vulnerability affects unknown code of... |
| CVE-2024-11492 | MEDIUM | 6.1 | 0.4% | Nov 20, 2024 | A vulnerability classified as problematic has been found in 115cms up to 20240807. This affects an unknown part of the f... |
| CVE-2024-11081 | — | — | — | Nov 20, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2024-52796 | MEDIUM | 5.3 | 0.5% | Nov 20, 2024 | Password Pusher, an open source application to communicate sensitive information over the web, comes with a configurable... |
| CVE-2024-52771 | CRITICAL | 9.1 | 0.6% | Nov 20, 2024 | DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_v... |
| CVE-2024-52770 | CRITICAL | 9.8 | 0.8% | Nov 20, 2024 | An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to... |
| CVE-2024-52769 | HIGH | 7.2 | 0.7% | Nov 20, 2024 | An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to exe... |
| CVE-2024-52725 | MEDIUM | 4.9 | 0.5% | Nov 20, 2024 | SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code v... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now