2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51189 | MEDIUM | 4.8 | 0.4% | Nov 11, 2024 | TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)... |
| CVE-2024-51188 | MEDIUM | 4.8 | 0.4% | Nov 11, 2024 | TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)... |
| CVE-2024-51187 | MEDIUM | 4.8 | 0.4% | Nov 11, 2024 | TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS)... |
| CVE-2024-51186 | HIGH | 8 | 0.8% | Nov 11, 2024 | D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via the ping_addr paramete... |
| CVE-2024-48322 | HIGH | 8.1 | 0.8% | Nov 11, 2024 | UsersController.php in Run.codes 1.5.2 and older has a reset password race condition vulnerability. |
| CVE-2024-46965 | MEDIUM | 5.4 | 0.2% | Nov 11, 2024 | The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows a... |
| CVE-2024-36061 | CRITICAL | 9.8 | 1.1% | Nov 11, 2024 | EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrar... |
| CVE-2024-11078 | MEDIUM | 5.4 | 0.4% | Nov 11, 2024 | A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. Affected by this vuln... |
| CVE-2024-10315 | MEDIUM | 6.9 | 0.3% | Nov 11, 2024 | In Gliffy Online an insecure configuration was discovered in versions before 4.14.0-6. Reported by Alpha Inferno PVT LTD... |
| CVE-2024-51135 | CRITICAL | 9.8 | 1.0% | Nov 11, 2024 | An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows atta... |
| CVE-2024-50667 | CRITICAL | 9.8 | 6.5% | Nov 11, 2024 | The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv... |
| CVE-2024-11077 | CRITICAL | 9.8 | 0.6% | Nov 11, 2024 | A vulnerability, which was classified as critical, was found in code-projects Job Recruitment 1.0. Affected is an unknow... |
| CVE-2024-11076 | CRITICAL | 9.8 | 0.5% | Nov 11, 2024 | A vulnerability, which was classified as critical, has been found in code-projects Job Recruitment 1.0. This issue affec... |
| CVE-2024-11074 | CRITICAL | 9.8 | 0.5% | Nov 11, 2024 | A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. This vulnerability aff... |
| CVE-2024-45087 | MEDIUM | 4.8 | 0.2% | Nov 11, 2024 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileg... |
| CVE-2024-11073 | HIGH | 8.1 | 0.6% | Nov 11, 2024 | A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects ... |
| CVE-2024-10917 | MEDIUM | 5.3 | 0.4% | Nov 11, 2024 | In Eclipse OpenJ9 versions up to 0.47, the JNI function GetStringUTFLength may return an incorrect value which has wrapp... |
| CVE-2024-45088 | MEDIUM | 5.4 | 0.2% | Nov 11, 2024 | IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows authenticate... |
| CVE-2024-43439 | MEDIUM | 6.1 | 0.4% | Nov 11, 2024 | A flaw was found in moodle. H5P error messages require additional sanitizing to prevent a reflected cross-site scripting... |
| CVE-2024-51054 | MEDIUM | 4.8 | 0.4% | Nov 11, 2024 | A Cross Site Scriptng (XSS) vulnerability was found in /omrs/admin/search.php in PHPGurukul Online Marriage Registration... |
| CVE-2024-50991 | MEDIUM | 4.8 | 0.4% | Nov 11, 2024 | A Cross Site Scripting (XSS) vulnerability was found in /ums-sp/admin/registered-users.php in PHPGurukul User Management... |
| CVE-2024-50990 | MEDIUM | 6.1 | 0.4% | Nov 11, 2024 | A Reflected Cross Site Scriptng (XSS) vulnerability was found in /omrs/user/search.php in PHPGurukul Online Marriage Reg... |
| CVE-2024-50989 | CRITICAL | 9.8 | 0.5% | Nov 11, 2024 | A SQL injection vulnerability in /omrs/admin/search.php in PHPGurukul Online Marriage Registration System v1.0 allows an... |
| CVE-2024-47131 | HIGH | 7.8 | 0.3% | Nov 11, 2024 | If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a sta... |
| CVE-2024-39605 | HIGH | 7.8 | 2.9% | Nov 11, 2024 | If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a sta... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now