2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39302 | LOW | 3.7 | 0.5% | Jun 28, 2024 | BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be... |
| CVE-2024-3995 | LOW | 2 | 0.6% | Jun 28, 2024 | In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins. |
| CVE-2024-38531 | LOW | 3.6 | 0.1% | Jun 28, 2024 | Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A bui... |
| CVE-2024-29038 | LOW | 3.3 | 0.4% | Jun 28, 2024 | tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate ar... |
| CVE-2024-39157 | LOW | 3.8 | 0.2% | Jun 27, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mu... |
| CVE-2024-39156 | LOW | 3.8 | 0.2% | Jun 27, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mud... |
| CVE-2024-39458 | LOW | 3.1 | 0.4% | Jun 26, 2024 | When Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message c... |
| CVE-2024-6344 | LOW | 2.4 | 0.4% | Jun 26, 2024 | A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an ... |
| CVE-2024-28830 | LOW | 2.7 | 0.3% | Jun 26, 2024 | Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p7, <2.2.0p28, <2.1.0p45 and <... |
| CVE-2024-37141 | LOW | 3.5 | 0.3% | Jun 26, 2024 | Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an open redirect vulnerab... |
| CVE-2024-29177 | LOW | 2.7 | 0.3% | Jun 26, 2024 | Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a disclosure of temporary... |
| CVE-2024-38364 | LOW | 2.6 | 0.4% | Jun 26, 2024 | DSpace is an open source software is a turnkey repository application used by more than 2,000 organizations and institut... |
| CVE-2024-6299 | LOW | 3.7 | 0.2% | Jun 25, 2024 | Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an... |
| CVE-2024-6295 | LOW | 3.9 | 0.2% | Jun 25, 2024 | udn News Android APP stores the unencrypted user session in the local database when user log into the application. A mal... |
| CVE-2024-6294 | LOW | 3.9 | 0.2% | Jun 25, 2024 | udn News Android APP stores the user session in logcat file when user log into the APP. A malicious APP or an attacker w... |
| CVE-2024-4839 | LOW | 3.3 | 0.2% | Jun 24, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the 'Servers Configurations' function of the parisneo/lollms... |
| CVE-2024-3121 | LOW | 3.3 | 0.4% | Jun 24, 2024 | A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version... |
| CVE-2024-4841 | LOW | 3.3 | 0.7% | Jun 23, 2024 | A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode... |
| CVE-2024-37352 | LOW | 3.4 | 0.3% | Jun 20, 2024 | There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06 that... |
| CVE-2024-37351 | LOW | 3.4 | 0.3% | Jun 20, 2024 | There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Att... |
| CVE-2024-37349 | LOW | 3.4 | 0.3% | Jun 20, 2024 | There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Att... |
| CVE-2024-37348 | LOW | 3.4 | 0.3% | Jun 20, 2024 | There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Att... |
| CVE-2024-37347 | LOW | 3.4 | 0.3% | Jun 20, 2024 | There is a cross-site scripting vulnerability in the pool configuration component of the management UI of Absolute Secur... |
| CVE-2024-37344 | LOW | 3.4 | 0.3% | Jun 20, 2024 | There is a cross-site scripting vulnerability in the Policy management UI of Absolute Secure Access prior to version 13.... |
| CVE-2024-38358 | LOW | 2.9 | 0.2% | Jun 19, 2024 | Wasmer is a web assembly (wasm) Runtime supporting WASIX, WASI and Emscripten. If the preopened directory has a symlink ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now