2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51993 | LOW | 3.4 | 0.1% | Nov 7, 2024 | Combodo iTop is a web based IT Service Management tool. An attacker accessing a backup file or the database can read som... |
| CVE-2024-51989 | HIGH | 7.1 | 0.3% | Nov 7, 2024 | Password Pusher is an open source application to communicate sensitive information over the web. A cross-site scripting ... |
| CVE-2024-51758 | LOW | 2.3 | 0.5% | Nov 7, 2024 | Filament is a collection of full-stack components for accelerated Laravel development. All Filament features that intera... |
| CVE-2024-51428 | HIGH | 7.5 | 0.5% | Nov 7, 2024 | An issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a crafted data channel pack... |
| CVE-2024-48290 | MEDIUM | 4.3 | 0.2% | Nov 7, 2024 | An issue in the Bluetooth Low Energy implementation of Realtek RTL8762E BLE SDK v1.4.0 allows attackers to cause a Denia... |
| CVE-2024-47073 | CRITICAL | 9.1 | 1.2% | Nov 7, 2024 | DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into... |
| CVE-2024-45794 | HIGH | 8.8 | 0.7% | Nov 7, 2024 | devtron is an open source tool integration platform for Kubernetes. In affected versions an authenticated user (with min... |
| CVE-2024-10967 | HIGH | 7.5 | 0.7% | Nov 7, 2024 | A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an ... |
| CVE-2024-10966 | HIGH | 8.8 | 3.1% | Nov 7, 2024 | A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by th... |
| CVE-2024-48954 | MEDIUM | 6.4 | 0.4% | Nov 7, 2024 | An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authentica... |
| CVE-2024-48953 | HIGH | 7.5 | 0.3% | Nov 7, 2024 | An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authenticatio... |
| CVE-2024-48952 | MEDIUM | 6.4 | 0.3% | Nov 7, 2024 | An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access... |
| CVE-2024-48951 | HIGH | 7.5 | 0.3% | Nov 7, 2024 | An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoin... |
| CVE-2024-48950 | HIGH | 7.5 | 0.3% | Nov 7, 2024 | An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing u... |
| CVE-2024-40715 | HIGH | 7.7 | 0.6% | Nov 7, 2024 | A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform ... |
| CVE-2024-10965 | MEDIUM | 6.5 | 0.5% | Nov 7, 2024 | A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an un... |
| CVE-2024-10964 | CRITICAL | 9.8 | 0.6% | Nov 7, 2024 | A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handle_add_p... |
| CVE-2024-8378 | MEDIUM | 4.8 | 0.3% | Nov 7, 2024 | The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_uploa... |
| CVE-2024-10963 | HIGH | 7.4 | 0.8% | Nov 7, 2024 | A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This ... |
| CVE-2024-10668 | HIGH | 7.5 | 0.4% | Nov 7, 2024 | There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root... |
| CVE-2024-9926 | MEDIUM | 4.3 | 1.1% | Nov 7, 2024 | The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated ... |
| CVE-2024-43440 | HIGH | 7.5 | 0.6% | Nov 7, 2024 | A flaw was found in moodle. A local file may include risks when restoring block backups. |
| CVE-2024-43438 | HIGH | 7.5 | 0.5% | Nov 7, 2024 | A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients ... |
| CVE-2024-43436 | HIGH | 7.2 | 0.6% | Nov 7, 2024 | A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators. |
| CVE-2024-43434 | HIGH | 8.1 | 0.6% | Nov 7, 2024 | The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check,... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now