2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-11744 | CRITICAL | 9.8 | 0.7% | Nov 26, 2024 | A vulnerability has been found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. Affected... |
| CVE-2024-49052 | CRITICAL | 9.8 | 0.7% | Nov 26, 2024 | Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate p... |
| CVE-2024-49038 | CRITICAL | 9.6 | 1.0% | Nov 26, 2024 | Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorize... |
| CVE-2024-49035 | CRITICAL | 9.8 | 1.3% | Nov 26, 2024 | An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privil... |
| CVE-2024-11145 | CRITICAL | 9.8 | 1.0% | Nov 26, 2024 | Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker t... |
| CVE-2024-11705 | CRITICAL | 9.1 | 0.7% | Nov 26, 2024 | `NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segme... |
| CVE-2024-11704 | CRITICAL | 9.8 | 0.9% | Nov 26, 2024 | A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specif... |
| CVE-2024-11698 | CRITICAL | 9.8 | 0.7% | Nov 26, 2024 | A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mo... |
| CVE-2024-11693 | CRITICAL | 9.8 | 0.8% | Nov 26, 2024 | The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Wind... |
| CVE-2024-50375 | CRITICAL | 9.8 | 1.0% | Nov 26, 2024 | A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by ... |
| CVE-2024-50374 | CRITICAL | 9.8 | 1.5% | Nov 26, 2024 | A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff... |
| CVE-2024-50373 | CRITICAL | 9.8 | 1.3% | Nov 26, 2024 | A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff... |
| CVE-2024-50372 | CRITICAL | 9.8 | 1.3% | Nov 26, 2024 | A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff... |
| CVE-2024-50371 | CRITICAL | 9.8 | 1.3% | Nov 26, 2024 | A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff... |
| CVE-2024-50370 | CRITICAL | 9.8 | 1.5% | Nov 26, 2024 | A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff... |
| CVE-2024-11024 | CRITICAL | 9.8 | 0.7% | Nov 26, 2024 | The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in... |
| CVE-2024-11680 | CRITICAL | 9.8 | 91.6% | Nov 26, 2024 | ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated at... |
| CVE-2024-36248 | CRITICAL | 9.1 | 1.1% | Nov 26, 2024 | API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model... |
| CVE-2024-35244 | CRITICAL | 9.1 | 1.1% | Nov 26, 2024 | There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their ... |
| CVE-2024-33610 | CRITICAL | 9.1 | 45.1% | Nov 26, 2024 | "sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides log... |
| CVE-2024-28038 | CRITICAL | 9 | 2.6% | Nov 26, 2024 | The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More ... |
| CVE-2024-50672 | CRITICAL | 9.8 | 1.5% | Nov 25, 2024 | A NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to res... |
| CVE-2024-52787 | CRITICAL | 9.1 | 0.8% | Nov 25, 2024 | An issue in the upload_documents method of libre-chat v0.0.6 allows attackers to execute a path traversal via supplying ... |
| CVE-2024-11403 | CRITICAL | 9.8 | 0.6% | Nov 25, 2024 | There exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. Th... |
| CVE-2024-11664 | CRITICAL | 9.8 | 1.9% | Nov 25, 2024 | A vulnerability, which was classified as critical, has been found in eNMS up to 4.2. Affected by this issue is the funct... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now