2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-48011MEDIUM6.5Dell PowerProtect DD, versions prior to 7.7.5.50, contains an Exposure of Sensitive Information to an Unauthorized Actor...
CVE-2024-48010HIGH7.2Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerab...
CVE-2024-45759HIGH7.3Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of ...
CVE-2024-8424HIGH8.5Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe modu...
CVE-2024-51998HIGH8.6changedetection.io is a free open source web page change detection tool. The validation for the file URI scheme falls sh...
CVE-2024-51987MEDIUM5.4Duende.AccessTokenManagement.OpenIdConnect is a set of .NET libraries that manage OAuth and OpenId Connect access tokens...
CVE-2024-47072HIGH7.5XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker t...
CVE-2024-8810MEDIUM6.5A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from a...
CVE-2024-51434MEDIUM6.1Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier.
CVE-2024-50766CRITICAL9.8SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter.
CVE-2024-49524MEDIUM5.4Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2024-49523MEDIUM5.4Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-46961HIGH8.1The Inshot com.downloader.privatebrowser (aka Video Downloader - XDownloader) application through 1.3.5 for Android allo...
CVE-2024-46960HIGH8.8The ASD com.rocks.video.downloader (aka HD Video Downloader All Format) application through 7.0.129 for Android allows a...
CVE-2024-36064MEDIUM6.2The NLL com.nll.cb (aka ACR Phone) application through 0.330-playStore-NoAccessibility-arm8 for Android allows any insta...
CVE-2024-36063HIGH7.5The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no p...
CVE-2024-36062MEDIUM4The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed app...
CVE-2024-10824MEDIUM6.5An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal user...
CVE-2024-50599MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, aff...
CVE-2024-10975HIGH7.7Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume cr...
CVE-2024-10007CRITICAL9.1A path collision and arbitrary code execution vulnerability was identified in GitHub Enterprise Server that allowed cont...
CVE-2024-10969CRITICAL9.8A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been rated as critical. Affected by t...
CVE-2024-10968CRITICAL9.8A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. Affected b...
CVE-2024-51995HIGH7.1Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specif...
CVE-2024-51994MEDIUM5.4Combodo iTop is a web based IT Service Management tool. In affected versions uploading a text file containing some java ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now