2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48011 | MEDIUM | 6.5 | 0.3% | Nov 8, 2024 | Dell PowerProtect DD, versions prior to 7.7.5.50, contains an Exposure of Sensitive Information to an Unauthorized Actor... |
| CVE-2024-48010 | HIGH | 7.2 | 0.4% | Nov 8, 2024 | Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerab... |
| CVE-2024-45759 | HIGH | 7.3 | 0.1% | Nov 8, 2024 | Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of ... |
| CVE-2024-8424 | HIGH | 8.5 | 0.2% | Nov 8, 2024 | Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe modu... |
| CVE-2024-51998 | HIGH | 8.6 | 0.7% | Nov 8, 2024 | changedetection.io is a free open source web page change detection tool. The validation for the file URI scheme falls sh... |
| CVE-2024-51987 | MEDIUM | 5.4 | 0.2% | Nov 8, 2024 | Duende.AccessTokenManagement.OpenIdConnect is a set of .NET libraries that manage OAuth and OpenId Connect access tokens... |
| CVE-2024-47072 | HIGH | 7.5 | 2.0% | Nov 8, 2024 | XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker t... |
| CVE-2024-8810 | MEDIUM | 6.5 | 0.4% | Nov 7, 2024 | A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from a... |
| CVE-2024-51434 | MEDIUM | 6.1 | 0.3% | Nov 7, 2024 | Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier. |
| CVE-2024-50766 | CRITICAL | 9.8 | 0.5% | Nov 7, 2024 | SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter. |
| CVE-2024-49524 | MEDIUM | 5.4 | 0.4% | Nov 7, 2024 | Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2024-49523 | MEDIUM | 5.4 | 0.3% | Nov 7, 2024 | Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-46961 | HIGH | 8.1 | 0.4% | Nov 7, 2024 | The Inshot com.downloader.privatebrowser (aka Video Downloader - XDownloader) application through 1.3.5 for Android allo... |
| CVE-2024-46960 | HIGH | 8.8 | 0.4% | Nov 7, 2024 | The ASD com.rocks.video.downloader (aka HD Video Downloader All Format) application through 7.0.129 for Android allows a... |
| CVE-2024-36064 | MEDIUM | 6.2 | 0.2% | Nov 7, 2024 | The NLL com.nll.cb (aka ACR Phone) application through 0.330-playStore-NoAccessibility-arm8 for Android allows any insta... |
| CVE-2024-36063 | HIGH | 7.5 | 0.3% | Nov 7, 2024 | The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no p... |
| CVE-2024-36062 | MEDIUM | 4 | 0.2% | Nov 7, 2024 | The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed app... |
| CVE-2024-10824 | MEDIUM | 6.5 | 0.3% | Nov 7, 2024 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal user... |
| CVE-2024-50599 | MEDIUM | 6.1 | 61.3% | Nov 7, 2024 | A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, aff... |
| CVE-2024-10975 | HIGH | 7.7 | 0.5% | Nov 7, 2024 | Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume cr... |
| CVE-2024-10007 | CRITICAL | 9.1 | 0.8% | Nov 7, 2024 | A path collision and arbitrary code execution vulnerability was identified in GitHub Enterprise Server that allowed cont... |
| CVE-2024-10969 | CRITICAL | 9.8 | 0.6% | Nov 7, 2024 | A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been rated as critical. Affected by t... |
| CVE-2024-10968 | CRITICAL | 9.8 | 0.7% | Nov 7, 2024 | A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. Affected b... |
| CVE-2024-51995 | HIGH | 7.1 | 0.4% | Nov 7, 2024 | Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specif... |
| CVE-2024-51994 | MEDIUM | 5.4 | 0.3% | Nov 7, 2024 | Combodo iTop is a web based IT Service Management tool. In affected versions uploading a text file containing some java ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now