2024 CVE Vulnerabilities
39,242 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34789 | MEDIUM | 6.5 | 0.3% | Jun 3, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WP Hait Pos... |
| CVE-2024-34754 | MEDIUM | 5.3 | 0.3% | Jun 3, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Contact Form Widget.This issue aff... |
| CVE-2024-3829 | CRITICAL | 9.1 | 0.9% | Jun 3, 2024 | qdrant/qdrant version 1.9.0-dev is vulnerable to arbitrary file read and write during the snapshot recovery process. Att... |
| CVE-2024-35635 | MEDIUM | 4.9 | 0.2% | Jun 3, 2024 | Server-Side Request Forgery (SSRF) vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from... |
| CVE-2024-35633 | MEDIUM | 4.9 | 0.3% | Jun 3, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Creative Themes Blocksy Companion blocksy-companion.This issue affec... |
| CVE-2024-23670 | HIGH | 8.8 | 0.4% | Jun 3, 2024 | An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,... |
| CVE-2024-23668 | HIGH | 8.8 | 0.7% | Jun 3, 2024 | An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,... |
| CVE-2024-23667 | HIGH | 8.8 | 0.4% | Jun 3, 2024 | An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,... |
| CVE-2024-23665 | HIGH | 8.8 | 0.5% | Jun 3, 2024 | Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, ... |
| CVE-2024-23664 | MEDIUM | 6.1 | 0.3% | Jun 3, 2024 | A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and be... |
| CVE-2024-23363 | HIGH | 7.5 | 0.3% | Jun 3, 2024 | Transient DOS while processing an improperly formatted Fine Time Measurement (FTM) management frame. |
| CVE-2024-23360 | HIGH | 7.8 | 0.1% | Jun 3, 2024 | Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers. |
| CVE-2024-21478 | MEDIUM | 5.5 | 0.1% | Jun 3, 2024 | transient DOS when setting up a fence callback to free a KGSL memory entry object during DMA. |
| CVE-2024-5404 | CRITICAL | 9.8 | 0.5% | Jun 3, 2024 | An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mech... |
| CVE-2024-35639 | MEDIUM | 5.9 | 0.3% | Jun 3, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webliberty Simple ... |
| CVE-2024-35638 | MEDIUM | 4.3 | 0.2% | Jun 3, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in JumpDEMAND Inc. ActiveDEMAND.This issue affects ActiveDEMAND: from n/... |
| CVE-2024-35637 | MEDIUM | 4.4 | 0.2% | Jun 3, 2024 | Server-Side Request Forgery (SSRF) vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin... |
| CVE-2024-36964 | MEDIUM | 5.5 | 0.2% | Jun 3, 2024 | In the Linux kernel, the following vulnerability has been resolved: fs/9p: only translate RWX permissions for plain 9P2... |
| CVE-2024-36963 | HIGH | 7.8 | 0.2% | Jun 3, 2024 | In the Linux kernel, the following vulnerability has been resolved: tracefs: Reset permissions on remount if permission... |
| CVE-2024-36962 | MEDIUM | 5.5 | 0.2% | Jun 3, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Queue RX packets in IRQ handler instea... |
| CVE-2024-36961 | MEDIUM | 5.5 | 0.1% | Jun 3, 2024 | In the Linux kernel, the following vulnerability has been resolved: thermal/debugfs: Fix two locking issues with therma... |
| CVE-2024-36960 | HIGH | 7.1 | 0.3% | Jun 3, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix invalid reads in fence signaled eve... |
| CVE-2024-35640 | MEDIUM | 5.9 | 0.3% | Jun 3, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tomas Corde... |
| CVE-2024-31493 | MEDIUM | 6.5 | 0.5% | Jun 3, 2024 | An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3... |
| CVE-2024-23107 | MEDIUM | 5.5 | 0.2% | Jun 3, 2024 | An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now