2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9526 | MEDIUM | 5.4 | 0.2% | Nov 18, 2024 | There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipel... |
| CVE-2024-8781 | HIGH | 8.7 | 0.2% | Nov 18, 2024 | Execution with Unnecessary Privileges, : Improper Protection of Alternate Path vulnerability in TR7 Application Security... |
| CVE-2024-11318 | HIGH | 7.5 | 0.9% | Nov 18, 2024 | An IDOR (Insecure Direct Object Reference) vulnerability has been discovered in AbsysNet, affecting version 2.3.1. This ... |
| CVE-2024-11303 | HIGH | 8.7 | 1.8% | Nov 18, 2024 | The pathname of the root directory to a Restricted Directory ('Path Traversal') vulnerability in Korenix JetPort 5601 al... |
| CVE-2024-52318 | MEDIUM | 6.1 | 1.7% | Nov 18, 2024 | Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31,... |
| CVE-2024-3370 | HIGH | 8.8 | 0.3% | Nov 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egebilgi Software ... |
| CVE-2024-52317 | MEDIUM | 6.5 | 2.0% | Nov 18, 2024 | Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response u... |
| CVE-2024-52316 | CRITICAL | 9.8 | 6.3% | Nov 18, 2024 | Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication... |
| CVE-2024-48901 | MEDIUM | 4.3 | 0.3% | Nov 18, 2024 | A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a re... |
| CVE-2024-48898 | MEDIUM | 4.3 | 0.3% | Nov 18, 2024 | A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from othe... |
| CVE-2024-48897 | MEDIUM | 4.3 | 0.3% | Nov 18, 2024 | A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds th... |
| CVE-2024-48896 | MEDIUM | 4.3 | 0.4% | Nov 18, 2024 | A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' na... |
| CVE-2024-11319 | MEDIUM | 4.8 | 0.5% | Nov 18, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS ... |
| CVE-2024-11023 | MEDIUM | 6.1 | 0.1% | Nov 18, 2024 | Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncU... |
| CVE-2024-42392 | HIGH | 7.5 | 0.2% | Nov 18, 2024 | Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite l... |
| CVE-2024-42391 | MEDIUM | 5.3 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex... |
| CVE-2024-42390 | MEDIUM | 5.3 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex... |
| CVE-2024-42389 | MEDIUM | 5.3 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex... |
| CVE-2024-42388 | MEDIUM | 5.3 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex... |
| CVE-2024-42387 | MEDIUM | 5.3 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex... |
| CVE-2024-42386 | HIGH | 7.5 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unex... |
| CVE-2024-42385 | HIGH | 7 | 0.1% | Nov 18, 2024 | Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bou... |
| CVE-2024-42384 | HIGH | 7.5 | 0.4% | Nov 18, 2024 | Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpect... |
| CVE-2024-42383 | CRITICAL | 9.8 | 0.3% | Nov 18, 2024 | Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value ... |
| CVE-2024-41974 | HIGH | 7.1 | 0.3% | Nov 18, 2024 | A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for cri... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now