2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52942 | MEDIUM | 5.4 | 0.3% | Nov 18, 2024 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated rem... |
| CVE-2024-52941 | MEDIUM | 5.4 | 0.3% | Nov 18, 2024 | An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated rem... |
| CVE-2024-11310 | HIGH | 7.5 | 0.7% | Nov 18, 2024 | The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulner... |
| CVE-2024-11309 | HIGH | 7.5 | 0.7% | Nov 18, 2024 | The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulner... |
| CVE-2024-11308 | MEDIUM | 5.5 | 0.2% | Nov 18, 2024 | The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore th... |
| CVE-2024-52940 | HIGH | 7.5 | 1.2% | Nov 18, 2024 | AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address wi... |
| CVE-2024-43704 | HIGH | 8.4 | 0.2% | Nov 18, 2024 | Software installed and run as a non-privileged user may conduct improper GPU system calls to gain access to the graphics... |
| CVE-2024-52926 | MEDIUM | 6.5 | 0.2% | Nov 18, 2024 | Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent. |
| CVE-2024-52922 | MEDIUM | 6.5 | 0.3% | Nov 18, 2024 | In Bitcoin Core before 25.1, an attacker can cause a node to not download the latest block, because there can be minutes... |
| CVE-2024-52921 | MEDIUM | 5.3 | 0.4% | Nov 18, 2024 | In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block. |
| CVE-2024-52920 | HIGH | 7.5 | 0.6% | Nov 18, 2024 | Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA ... |
| CVE-2024-52919 | MEDIUM | 6.5 | 0.3% | Nov 18, 2024 | Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via ... |
| CVE-2024-52918 | MEDIUM | 6.5 | 0.5% | Nov 18, 2024 | Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and ap... |
| CVE-2024-52917 | MEDIUM | 6.5 | 0.3% | Nov 18, 2024 | Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received ... |
| CVE-2024-52916 | HIGH | 7.5 | 0.5% | Nov 18, 2024 | Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty h... |
| CVE-2024-52915 | HIGH | 7.5 | 0.6% | Nov 18, 2024 | Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV m... |
| CVE-2024-52914 | HIGH | 7.5 | 0.5% | Nov 18, 2024 | In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed tr... |
| CVE-2024-52913 | MEDIUM | 5.3 | 0.4% | Nov 18, 2024 | In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because ... |
| CVE-2024-52912 | HIGH | 7.5 | 0.5% | Nov 18, 2024 | Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offse... |
| CVE-2024-38828 | MEDIUM | 5.3 | 0.7% | Nov 18, 2024 | Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack. |
| CVE-2024-11306 | MEDIUM | 6.9 | 0.5% | Nov 18, 2024 | A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. Th... |
| CVE-2024-11305 | MEDIUM | 6.3 | 3.7% | Nov 18, 2024 | A vulnerability classified as critical was found in Altenergy Power Control Software up to 20241108. This vulnerability ... |
| CVE-2024-0793 | HIGH | 7.7 | 0.6% | Nov 17, 2024 | A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking... |
| CVE-2024-52876 | HIGH | 7.5 | 0.5% | Nov 17, 2024 | Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows una... |
| CVE-2024-52872 | HIGH | 7.5 | 0.4% | Nov 17, 2024 | In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now