2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50306 | CRITICAL | 9.1 | 1.6% | Nov 14, 2024 | Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traff... |
| CVE-2024-50305 | HIGH | 7.5 | 0.9% | Nov 14, 2024 | Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic S... |
| CVE-2024-47916 | HIGH | 7.5 | 0.5% | Nov 14, 2024 | Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2024-47915 | HIGH | 7.5 | 0.4% | Nov 14, 2024 | VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2024-47914 | MEDIUM | 4.5 | 0.2% | Nov 14, 2024 | VaeMendis - CWE-352: Cross-Site Request Forgery (CSRF) |
| CVE-2024-45254 | HIGH | 7.5 | 0.4% | Nov 14, 2024 | VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2024-45253 | HIGH | 7.5 | 0.5% | Nov 14, 2024 | Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
| CVE-2024-38479 | HIGH | 7.5 | 0.9% | Nov 14, 2024 | Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 ... |
| CVE-2024-2552 | MEDIUM | 6 | 0.5% | Nov 14, 2024 | A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass... |
| CVE-2024-2551 | HIGH | 7.5 | 0.5% | Nov 14, 2024 | A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to st... |
| CVE-2024-2550 | HIGH | 7.5 | 0.5% | Nov 14, 2024 | A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an u... |
| CVE-2024-7787 | MEDIUM | 5.1 | 0.4% | Nov 14, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ITG Compute... |
| CVE-2024-11206 | HIGH | 7.5 | 0.4% | Nov 14, 2024 | Unauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user info... |
| CVE-2024-9186 | HIGH | 8.6 | 2.2% | Nov 14, 2024 | The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugi... |
| CVE-2024-10146 | MEDIUM | 5.4 | 0.6% | Nov 14, 2024 | The Simple File List WordPress plugin before 6.1.13 does not sanitise and escape a generated URL before outputting it ba... |
| CVE-2024-5082 | HIGH | 7.1 | 1.9% | Nov 14, 2024 | A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2. This issue affects Nexus Rep... |
| CVE-2024-5083 | MEDIUM | 5.1 | 0.4% | Nov 14, 2024 | A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2 This issue affects Nexus... |
| CVE-2024-40410 | MEDIUM | 4.8 | 0.1% | Nov 13, 2024 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for ... |
| CVE-2024-40408 | HIGH | 7.3 | 0.3% | Nov 13, 2024 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create P... |
| CVE-2024-40407 | HIGH | 7.5 | 0.4% | Nov 13, 2024 | A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root pat... |
| CVE-2024-40405 | HIGH | 8.1 | 0.4% | Nov 13, 2024 | Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a ... |
| CVE-2024-40404 | CRITICAL | 9.8 | 0.4% | Nov 13, 2024 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endp... |
| CVE-2024-51027 | MEDIUM | 6.5 | 6.8% | Nov 13, 2024 | Ruijie NBR800G gateway NBR_RGOS_11.1(6)B4P9 is vulnerable to command execution in /itbox_pi/networksafe.php via the prov... |
| CVE-2024-50956 | MEDIUM | 6.5 | 0.3% | Nov 13, 2024 | A buffer overflow in the RecvSocketData function of Inovance HCPLC_AM401-CPU1608TPTN 21.38.0.0, HCPLC_AM402-CPU1608TPTN ... |
| CVE-2024-50955 | HIGH | 7.5 | 0.4% | Nov 13, 2024 | An issue in how XINJE XD5E-24R and XL5E-16T v3.5.3b handles TCP protocol messages allows attackers to cause a Denial of ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now