2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24453 | MEDIUM | 5.9 | 0.3% | Nov 15, 2024 | An invalid memory access when handling the ProtocolIE_ID field of E-RAB NotToBeModifiedBearerModInd information element ... |
| CVE-2024-24452 | MEDIUM | 5.9 | 0.4% | Nov 15, 2024 | An invalid memory access when handling the ProtocolIE_ID field of E-RAB Release Indication messages in Athonet vEPC MME ... |
| CVE-2024-11259 | MEDIUM | 6.1 | 0.4% | Nov 15, 2024 | A vulnerability, which was classified as problematic, has been found in code-projects Farmacia 1.0. This issue affects s... |
| CVE-2024-11258 | CRITICAL | 9.8 | 0.8% | Nov 15, 2024 | A vulnerability classified as critical was found in 1000 Projects Beauty Parlour Management System 1.0. This vulnerabili... |
| CVE-2024-11257 | CRITICAL | 9.8 | 0.7% | Nov 15, 2024 | A vulnerability classified as critical has been found in 1000 Projects Beauty Parlour Management System 1.0. This affect... |
| CVE-2024-11256 | CRITICAL | 9.8 | 0.7% | Nov 15, 2024 | A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. This issue af... |
| CVE-2024-10934 | CRITICAL | 9.8 | 0.4% | Nov 15, 2024 | In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS client and s... |
| CVE-2024-51330 | MEDIUM | 5.1 | 0.2% | Nov 15, 2024 | An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-proce... |
| CVE-2024-51142 | MEDIUM | 5.4 | 0.3% | Nov 15, 2024 | Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey p... |
| CVE-2024-51141 | HIGH | 7.8 | 0.2% | Nov 15, 2024 | An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAut... |
| CVE-2024-51037 | MEDIUM | 5.3 | 0.3% | Nov 15, 2024 | An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature... |
| CVE-2024-45971 | CRITICAL | 9.8 | 0.6% | Nov 15, 2024 | Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c... |
| CVE-2024-45970 | CRITICAL | 9.8 | 0.6% | Nov 15, 2024 | Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd75626... |
| CVE-2024-45969 | HIGH | 7.5 | 0.5% | Nov 15, 2024 | NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e35... |
| CVE-2024-45608 | HIGH | 8.8 | 0.5% | Nov 15, 2024 | GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing it... |
| CVE-2024-43418 | MEDIUM | 6.1 | 0.4% | Nov 15, 2024 | GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI ... |
| CVE-2024-43417 | MEDIUM | 6.1 | 0.4% | Nov 15, 2024 | GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI ... |
| CVE-2024-41679 | HIGH | 8.8 | 0.5% | Nov 15, 2024 | GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability... |
| CVE-2024-24446 | MEDIUM | 6.5 | 0.3% | Nov 15, 2024 | An uninitialized pointer dereference in OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Ser... |
| CVE-2024-24431 | HIGH | 7.5 | 0.6% | Nov 15, 2024 | A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service... |
| CVE-2024-24426 | HIGH | 7.5 | 0.5% | Nov 15, 2024 | Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation ... |
| CVE-2024-24425 | MEDIUM | 6.5 | 0.4% | Nov 15, 2024 | Magma v1.8.0 and OAI EPC Federation v1.20 were discovered to contain an out-of-bounds read in the amf_as_establish_req f... |
| CVE-2024-23169 | MEDIUM | 4.6 | 0.3% | Nov 15, 2024 | The web interface in RSA NetWitness 11.7.2.0 allows Cross-Site Scripting (XSS) via the Where textbox on the Reports scre... |
| CVE-2024-52522 | MEDIUM | 5.4 | 0.2% | Nov 15, 2024 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure h... |
| CVE-2024-52514 | LOW | 3.5 | 0.5% | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being bloc... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now