2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42776 | HIGH | 7.2 | 0.5% | Aug 22, 2024 | Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php. |
| CVE-2024-42774 | HIGH | 7.5 | 0.4% | Aug 22, 2024 | An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0,... |
| CVE-2024-42772 | HIGH | 7.5 | 0.5% | Aug 22, 2024 | An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which... |
| CVE-2024-42490 | HIGH | 7.5 | 0.6% | Aug 22, 2024 | authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentica... |
| CVE-2024-36444 | HIGH | 8.1 | 0.5% | Aug 22, 2024 | cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device... |
| CVE-2024-36442 | HIGH | 8.8 | 0.7% | Aug 22, 2024 | cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrar... |
| CVE-2024-36443 | HIGH | 7.6 | 0.6% | Aug 22, 2024 | Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonym... |
| CVE-2024-39745 | HIGH | 7.5 | 0.3% | Aug 22, 2024 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that ... |
| CVE-2024-8071 | HIGH | 7.2 | 0.3% | Aug 22, 2024 | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can... |
| CVE-2024-40886 | HIGH | 8.8 | 0.2% | Aug 22, 2024 | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the... |
| CVE-2024-7384 | HIGH | 8.8 | 1.0% | Aug 22, 2024 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v... |
| CVE-2024-39576 | HIGH | 8.8 | 0.2% | Aug 22, 2024 | Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low pri... |
| CVE-2024-43033 | HIGH | 8.8 | 1.0% | Aug 22, 2024 | JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via... |
| CVE-2024-7980 | HIGH | 7.8 | 0.3% | Aug 21, 2024 | Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to... |
| CVE-2024-7979 | HIGH | 7.8 | 0.2% | Aug 21, 2024 | Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to... |
| CVE-2024-7977 | HIGH | 7.8 | 0.3% | Aug 21, 2024 | Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to... |
| CVE-2024-7974 | HIGH | 8.8 | 0.5% | Aug 21, 2024 | Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially ... |
| CVE-2024-7973 | HIGH | 8.8 | 0.7% | Aug 21, 2024 | Heap buffer overflow in PDFium in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform an out of bo... |
| CVE-2024-7972 | HIGH | 8.8 | 0.6% | Aug 21, 2024 | Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially perf... |
| CVE-2024-7969 | HIGH | 8.8 | 0.5% | Aug 21, 2024 | Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2024-7968 | HIGH | 8.8 | 0.5% | Aug 21, 2024 | Use after free in Autofill in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had convinced the user ... |
| CVE-2024-7967 | HIGH | 8.8 | 0.6% | Aug 21, 2024 | Heap buffer overflow in Fonts in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit h... |
| CVE-2024-7966 | HIGH | 8.8 | 0.6% | Aug 21, 2024 | Out of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had compromise... |
| CVE-2024-7965 | HIGH | 8.8 | 17.2% | Aug 21, 2024 | Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially expl... |
| CVE-2024-7964 | HIGH | 8.8 | 0.6% | Aug 21, 2024 | Use after free in Passwords in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to potentially ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now