2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52300 | CRITICAL | 9 | 0.4% | Nov 13, 2024 | macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't ... |
| CVE-2024-52299 | HIGH | 7.5 | 0.5% | Nov 13, 2024 | macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFViewerService... |
| CVE-2024-52298 | HIGH | 7.5 | 0.7% | Nov 13, 2024 | macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The PDF Viewer macro allows an attacker to view an... |
| CVE-2024-52295 | CRITICAL | 9.8 | 0.8% | Nov 13, 2024 | DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and... |
| CVE-2024-52293 | HIGH | 7.2 | 1.3% | Nov 13, 2024 | Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function Fi... |
| CVE-2024-50972 | HIGH | 7.2 | 0.7% | Nov 13, 2024 | A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attacker... |
| CVE-2024-50971 | HIGH | 7.2 | 0.7% | Nov 13, 2024 | A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to... |
| CVE-2024-50970 | HIGH | 8.8 | 0.5% | Nov 13, 2024 | A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote atta... |
| CVE-2024-50969 | MEDIUM | 6.1 | 0.5% | Nov 13, 2024 | A Reflected cross-site scripting (XSS) vulnerability in browse.php of Code-projects Jonnys Liquor 1.0 allows remote atta... |
| CVE-2024-11175 | MEDIUM | 4.8 | 0.5% | Nov 13, 2024 | A vulnerability was found in Public CMS 5.202406.d and classified as problematic. This issue affects some unknown proces... |
| CVE-2024-10013 | HIGH | 7.8 | 0.2% | Nov 13, 2024 | In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through... |
| CVE-2024-10012 | HIGH | 7.8 | 0.2% | Nov 13, 2024 | In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an i... |
| CVE-2024-9477 | MEDIUM | 6.1 | 0.2% | Nov 13, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AirTies Air... |
| CVE-2024-50854 | HIGH | 8.8 | 0.5% | Nov 13, 2024 | Tenda G3 v3.0 v15.11.0.20 was discovered to contain a stack overflow via the formSetPortMapping function. |
| CVE-2024-50853 | HIGH | 8.8 | 1.6% | Nov 13, 2024 | Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function. |
| CVE-2024-50852 | HIGH | 8.8 | 1.6% | Nov 13, 2024 | Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount ... |
| CVE-2024-49506 | HIGH | 7.3 | 0.1% | Nov 13, 2024 | Insecure creation of temporary files allows local users on systems with non-default configurations to cause denial of se... |
| CVE-2024-49505 | MEDIUM | 6.1 | 0.3% | Nov 13, 2024 | A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumblew... |
| CVE-2024-49504 | HIGH | 7 | 0.3% | Nov 13, 2024 | grub2 allowed attackers with access to the grub shell to access files on the encrypted disks. |
| CVE-2024-48900 | MEDIUM | 4.3 | 0.3% | Nov 13, 2024 | A vulnerability was found in Moodle. Additional checks are required to ensure users with permission to view badge recipi... |
| CVE-2024-48510 | CRITICAL | 9.8 | 2.1% | Nov 13, 2024 | Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code vi... |
| CVE-2024-11165 | MEDIUM | 5.7 | 0.1% | Nov 13, 2024 | An information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in ... |
| CVE-2024-48989 | HIGH | 7.5 | 0.5% | Nov 13, 2024 | A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacke... |
| CVE-2024-11159 | MEDIUM | 4.3 | 0.3% | Nov 13, 2024 | Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects T... |
| CVE-2024-47574 | HIGH | 7.8 | 0.5% | Nov 13, 2024 | A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now