2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49369 | CRITICAL | 9.8 | 2.9% | Nov 12, 2024 | Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generat... |
| CVE-2024-30133 | MEDIUM | 5.3 | 0.3% | Nov 12, 2024 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not suff... |
| CVE-2024-11006 | HIGH | 7.2 | 1.7% | Nov 12, 2024 | Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure be... |
| CVE-2024-11005 | HIGH | 7.2 | 1.7% | Nov 12, 2024 | Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure be... |
| CVE-2024-11004 | MEDIUM | 6.1 | 0.9% | Nov 12, 2024 | Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a... |
| CVE-2024-10945 | HIGH | 7.3 | 0.2% | Nov 12, 2024 | A Local Privilege Escalation vulnerability exists in the affected product. The vulnerability requires a local, low privi... |
| CVE-2024-10944 | HIGH | 8.4 | 0.5% | Nov 12, 2024 | A Remote Code Execution vulnerability exists in the affected product. The vulnerability requires a high level of permiss... |
| CVE-2024-10943 | CRITICAL | 9.1 | 0.5% | Nov 12, 2024 | An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets ac... |
| CVE-2024-10923 | HIGH | 8.6 | 0.3% | Nov 12, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ A... |
| CVE-2024-9420 | HIGH | 8.8 | 1.4% | Nov 12, 2024 | A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version... |
| CVE-2024-8495 | HIGH | 7.5 | 1.3% | Nov 12, 2024 | A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7... |
| CVE-2024-52297 | HIGH | 7.5 | 0.6% | Nov 12, 2024 | Tolgee is an open-source localization platform. Tolgee 3.81.1 included the all configuration properties in the PublicCon... |
| CVE-2024-52296 | MEDIUM | 6.5 | 0.3% | Nov 12, 2024 | libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with supp... |
| CVE-2024-50331 | HIGH | 7.5 | 1.1% | Nov 12, 2024 | An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak se... |
| CVE-2024-50330 | CRITICAL | 9.8 | 40.5% | Nov 12, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-50329 | HIGH | 8.8 | 1.7% | Nov 12, 2024 | Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo... |
| CVE-2024-50328 | HIGH | 7.2 | 1.7% | Nov 12, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-50327 | HIGH | 7.2 | 1.0% | Nov 12, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-50326 | HIGH | 7.2 | 25.8% | Nov 12, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-50324 | HIGH | 7.2 | 18.2% | Nov 12, 2024 | Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo... |
| CVE-2024-50323 | HIGH | 7.8 | 0.7% | Nov 12, 2024 | SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow... |
| CVE-2024-50322 | HIGH | 7.8 | 6.0% | Nov 12, 2024 | Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo... |
| CVE-2024-50321 | HIGH | 7.5 | 1.1% | Nov 12, 2024 | An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service. |
| CVE-2024-50320 | HIGH | 7.5 | 31.2% | Nov 12, 2024 | An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service. |
| CVE-2024-50319 | HIGH | 7.5 | 1.1% | Nov 12, 2024 | An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now