2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52521 | MEDIUM | 5.3 | 0.4% | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniquen... |
| CVE-2024-52520 | MEDIUM | 6.5 | 0.8% | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider... |
| CVE-2024-52519 | HIGH | 8.2 | 0.5% | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so ... |
| CVE-2024-52518 | MEDIUM | 5.4 | 0.5% | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or admini... |
| CVE-2024-52517 | MEDIUM | 5.9 | 0.6% | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. After storing "Global credentials" on the server, the API retur... |
| CVE-2024-52516 | MEDIUM | 4.3 | 0.4% | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. When a server is configured to only allow sharing with users th... |
| CVE-2024-52515 | MEDIUM | 6.5 | 0.7% | Nov 15, 2024 | Nextcloud Server is a self hosted personal cloud system. After an admin enables the default-disabled SVG preview provide... |
| CVE-2024-50655 | MEDIUM | 5.4 | 0.4% | Nov 15, 2024 | emlog pro <=2.3.18 is vulnerable to Cross Site Scripting (XSS), which allows attackers to write malicious JavaScript cod... |
| CVE-2024-50654 | HIGH | 7.5 | 1.6% | Nov 15, 2024 | lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quant... |
| CVE-2024-50653 | HIGH | 7.5 | 0.5% | Nov 15, 2024 | CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able t... |
| CVE-2024-44625 | HIGH | 8.8 | 14.9% | Nov 15, 2024 | Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go. |
| CVE-2024-39726 | HIGH | 8.2 | 0.7% | Nov 15, 2024 | IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity In... |
| CVE-2024-11248 | HIGH | 8.8 | 1.2% | Nov 15, 2024 | A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this issue is the function f... |
| CVE-2024-11247 | MEDIUM | 5.4 | 0.5% | Nov 15, 2024 | A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this... |
| CVE-2024-7865 | — | — | — | Nov 15, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2414. Reason: This candidate is a r... |
| CVE-2024-6413 | — | — | — | Nov 15, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2414. Reason: This candidate is a r... |
| CVE-2024-52555 | HIGH | 7.8 | 0.1% | Nov 15, 2024 | In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer... |
| CVE-2024-52526 | MEDIUM | 5.4 | 0.4% | Nov 15, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab... |
| CVE-2024-51497 | MEDIUM | 5.4 | 0.4% | Nov 15, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab... |
| CVE-2024-51496 | MEDIUM | 5.4 | 0.4% | Nov 15, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulne... |
| CVE-2024-51495 | MEDIUM | 5.4 | 0.4% | Nov 15, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab... |
| CVE-2024-51494 | MEDIUM | 5.4 | 0.4% | Nov 15, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab... |
| CVE-2024-51164 | CRITICAL | 9.1 | 0.7% | Nov 15, 2024 | Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allo... |
| CVE-2024-50724 | CRITICAL | 9.8 | 0.4% | Nov 15, 2024 | KASO v9.0 was discovered to contain a SQL injection vulnerability via the person_id parameter at /cardcase/editcard.jsp. |
| CVE-2024-50652 | MEDIUM | 4.3 | 0.3% | Nov 15, 2024 | A file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now