2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52513 | MEDIUM | 4.3 | 0.5% | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share li... |
| CVE-2024-52512 | MEDIUM | 6.1 | 0.4% | Nov 15, 2024 | user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that w... |
| CVE-2024-52511 | MEDIUM | 6.5 | 0.4% | Nov 15, 2024 | Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or v... |
| CVE-2024-52510 | HIGH | 7.5 | 0.7% | Nov 15, 2024 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client... |
| CVE-2024-52509 | MEDIUM | 5.7 | 0.5% | Nov 15, 2024 | Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly al... |
| CVE-2024-52508 | HIGH | 8.1 | 0.7% | Nov 15, 2024 | Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. When a user is trying to set up a mai... |
| CVE-2024-52507 | MEDIUM | 4.3 | 0.4% | Nov 15, 2024 | Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is s... |
| CVE-2024-50800 | MEDIUM | 5.4 | 0.4% | Nov 15, 2024 | Cross Site Scripting vulnerability in M2000 Smart4Web before v.5.020241004 allows a remote attacker to execute arbitrary... |
| CVE-2024-47759 | MEDIUM | 4.8 | 0.4% | Nov 15, 2024 | GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. T... |
| CVE-2024-46467 | HIGH | 7.8 | 0.2% | Nov 15, 2024 | By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical f... |
| CVE-2024-46466 | HIGH | 7.8 | 0.2% | Nov 15, 2024 | By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission)... |
| CVE-2024-46465 | HIGH | 7.8 | 0.2% | Nov 15, 2024 | By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical file... |
| CVE-2024-46463 | HIGH | 7.8 | 0.2% | Nov 15, 2024 | By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical file... |
| CVE-2024-46462 | HIGH | 7.8 | 0.2% | Nov 15, 2024 | By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical fil... |
| CVE-2024-46383 | LOW | 2.4 | 0.3% | Nov 15, 2024 | Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected ... |
| CVE-2024-41678 | MEDIUM | 6.1 | 0.5% | Nov 15, 2024 | GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI ... |
| CVE-2024-40638 | HIGH | 8.8 | 37.0% | Nov 15, 2024 | GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulner... |
| CVE-2024-24450 | MEDIUM | 5.3 | 1.4% | Nov 15, 2024 | Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN... |
| CVE-2024-24449 | MEDIUM | 6.5 | 0.4% | Nov 15, 2024 | An uninitialized pointer dereference in the NasPdu::NasPdu component of OpenAirInterface CN5G AMF up to v2.0.0 allows at... |
| CVE-2024-24447 | MEDIUM | 5.3 | 0.5% | Nov 15, 2024 | A buffer overflow in the ngap_amf_handle_pdu_session_resource_setup_response function of oai-cn5g-amf up to v2.0.0 allow... |
| CVE-2024-11251 | HIGH | 8.8 | 0.5% | Nov 15, 2024 | A vulnerability was found in erzhongxmu Jeewms up to 20241108. It has been rated as critical. This issue affects some un... |
| CVE-2024-11250 | CRITICAL | 9.8 | 0.7% | Nov 15, 2024 | A vulnerability was found in code-projects Inventory Management up to 1.0. It has been declared as critical. This vulner... |
| CVE-2024-52528 | CRITICAL | 9.3 | 0.6% | Nov 15, 2024 | Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for... |
| CVE-2024-52525 | HIGH | 7.5 | 0.3% | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unen... |
| CVE-2024-52523 | MEDIUM | 6.5 | 0.6% | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external stora... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now