2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39354 | HIGH | 7.8 | 0.3% | Nov 11, 2024 | If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a sta... |
| CVE-2024-11070 | MEDIUM | 5.4 | 0.4% | Nov 11, 2024 | A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS 5.202406.d. This issue affects... |
| CVE-2024-50263 | MEDIUM | 5.5 | 0.2% | Nov 11, 2024 | In the Linux kernel, the following vulnerability has been resolved: fork: only invoke khugepaged, ksm hooks if no error... |
| CVE-2024-34015 | LOW | 3.3 | 0.2% | Nov 11, 2024 | Sensitive information disclosure during file browsing due to improper symbolic link handling. The following products are... |
| CVE-2024-34014 | MEDIUM | 5.5 | 0.2% | Nov 11, 2024 | Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Ac... |
| CVE-2024-10345 | HIGH | 8.7 | 0.5% | Nov 11, 2024 | In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was ... |
| CVE-2024-10344 | HIGH | 8.7 | 0.5% | Nov 11, 2024 | In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the refuse function was id... |
| CVE-2024-10314 | HIGH | 8.7 | 0.5% | Nov 11, 2024 | In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the auto-generation functi... |
| CVE-2024-43437 | MEDIUM | 6.1 | 0.3% | Nov 11, 2024 | A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scrip... |
| CVE-2024-43435 | MEDIUM | 5.3 | 0.3% | Nov 11, 2024 | A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries ... |
| CVE-2024-43433 | MEDIUM | 5.3 | 0.3% | Nov 11, 2024 | A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Mo... |
| CVE-2024-43432 | MEDIUM | 5.3 | 0.3% | Nov 11, 2024 | A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, bu... |
| CVE-2024-43430 | MEDIUM | 5.3 | 0.3% | Nov 11, 2024 | A flaw was found in moodle. External API access to Quiz can override contained insufficient access control. |
| CVE-2024-43429 | MEDIUM | 5.3 | 0.3% | Nov 11, 2024 | A flaw was found in moodle. Some hidden user profile fields are visible in gradebook reports, which could result in user... |
| CVE-2024-43427 | LOW | 3.7 | 0.3% | Nov 11, 2024 | A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are ... |
| CVE-2024-11068 | CRITICAL | 9.8 | 1.2% | Nov 11, 2024 | The D-Link DSL6740C modem has an Incorrect Use of Privileged APIs vulnerability, allowing unauthenticated remote attacke... |
| CVE-2024-11067 | HIGH | 7.5 | 1.3% | Nov 11, 2024 | The D-Link DSL6740C modem has a Path Traversal Vulnerability, allowing unauthenticated remote attackers to exploit this ... |
| CVE-2024-11066 | HIGH | 7.2 | 1.8% | Nov 11, 2024 | The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil... |
| CVE-2024-11065 | HIGH | 7.2 | 1.3% | Nov 11, 2024 | The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil... |
| CVE-2024-11064 | HIGH | 7.2 | 1.3% | Nov 11, 2024 | The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil... |
| CVE-2024-11063 | HIGH | 7.2 | 1.3% | Nov 11, 2024 | The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil... |
| CVE-2024-11062 | HIGH | 7.2 | 1.3% | Nov 11, 2024 | The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil... |
| CVE-2024-11021 | MEDIUM | 5.4 | 0.3% | Nov 11, 2024 | Webopac from Grand Vice info has Stored Cross-site Scripting vulnerability. Remote attackers with regular privileges can... |
| CVE-2024-11020 | CRITICAL | 9.8 | 0.5% | Nov 11, 2024 | Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitr... |
| CVE-2024-52355 | MEDIUM | 5.4 | 0.3% | Nov 11, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MiKa OSM osm.This ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now