2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31448 | MEDIUM | 6.1 | 0.3% | Nov 5, 2024 | Combodo iTop is a simple, web based IT Service Management tool. By filling malicious code in a CSV content, an Cross-sit... |
| CVE-2024-51734 | HIGH | 8.7 | 0.4% | Nov 4, 2024 | Zope AccessControl provides a general security framework for use in Zope. In affected versions anonymous users can delet... |
| CVE-2024-51502 | MEDIUM | 5.1 | 0.5% | Nov 4, 2024 | loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the ... |
| CVE-2024-51501 | CRITICAL | 10 | 0.5% | Nov 4, 2024 | Refit is an automatic type-safe REST library for .NET Core, Xamarin and .NET The various header-related Refit attributes... |
| CVE-2024-51500 | HIGH | 7.5 | 0.4% | Nov 4, 2024 | Meshtastic firmware is a device firmware for the Meshtastic project. The Meshtastic firmware does not check for packets ... |
| CVE-2024-48061 | CRITICAL | 9.8 | 1.3% | Nov 4, 2024 | langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the ... |
| CVE-2024-48059 | MEDIUM | 6.1 | 0.3% | Nov 4, 2024 | gaizhenbiao/chuanhuchatgpt project, version <=20240802 is vulnerable to stored Cross-Site Scripting (XSS) in WebSocket s... |
| CVE-2024-48057 | MEDIUM | 6.1 | 0.2% | Nov 4, 2024 | localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriat... |
| CVE-2024-48052 | MEDIUM | 6.5 | 0.5% | Nov 4, 2024 | In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The re... |
| CVE-2024-48050 | CRITICAL | 9.8 | 0.8% | Nov 4, 2024 | In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. W... |
| CVE-2024-10805 | HIGH | 8.8 | 0.5% | Nov 4, 2024 | A vulnerability was found in code-projects University Event Management System 1.0. It has been classified as critical. T... |
| CVE-2024-51744 | LOW | 3.1 | 0.5% | Nov 4, 2024 | golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` c... |
| CVE-2024-48463 | MEDIUM | 6.5 | 0.6% | Nov 4, 2024 | Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within th... |
| CVE-2024-45185 | MEDIUM | 5.1 | 0.2% | Nov 4, 2024 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 108... |
| CVE-2024-45086 | MEDIUM | 5.5 | 0.4% | Nov 4, 2024 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when process... |
| CVE-2024-10791 | CRITICAL | 9.8 | 0.6% | Nov 4, 2024 | A vulnerability, which was classified as critical, has been found in Codezips Hospital Appointment System 1.0. This issu... |
| CVE-2024-34891 | MEDIUM | 6.8 | 0.3% | Nov 4, 2024 | Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrator... |
| CVE-2024-34885 | MEDIUM | 6.8 | 0.4% | Nov 4, 2024 | Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrato... |
| CVE-2024-30619 | HIGH | 7.5 | 0.4% | Nov 4, 2024 | Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the numb... |
| CVE-2024-30618 | MEDIUM | 6.1 | 0.4% | Nov 4, 2024 | A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary J... |
| CVE-2024-30617 | MEDIUM | 5.4 | 0.2% | Nov 4, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to in... |
| CVE-2024-30616 | HIGH | 8.8 | 0.6% | Nov 4, 2024 | Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sens... |
| CVE-2024-10768 | MEDIUM | 5.4 | 0.4% | Nov 4, 2024 | A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects... |
| CVE-2024-51329 | HIGH | 8.8 | 0.6% | Nov 4, 2024 | A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user in... |
| CVE-2024-51328 | MEDIUM | 6.1 | 0.4% | Nov 4, 2024 | Cross Site Scripting vulnerability in addcategory.php in projectworld's Travel Management System v1.0 allows remote atta... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now