2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49740 | MEDIUM | 5.5 | 0.1% | Aug 26, 2025 | In multiple locations, there is a possible crash loop due to resource exhaustion. This could lead to local denial of ser... |
| CVE-2024-47192 | MEDIUM | 5.3 | 0.1% | Aug 26, 2025 | An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker ... |
| CVE-2024-35203 | MEDIUM | 6.1 | 0.2% | Aug 26, 2025 | Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-site scripting (XSS) via a file, with JavaScript code as part o... |
| CVE-2024-39335 | CRITICAL | 9.1 | 0.3% | Aug 26, 2025 | Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed... |
| CVE-2024-47853 | HIGH | 8.8 | 0.3% | Aug 26, 2025 | An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases w... |
| CVE-2024-45753 | MEDIUM | 6.1 | 0.2% | Aug 26, 2025 | In Mahara 23.04.8 and 24.04.4, the external RSS feed block can cause XSS if the external feed XML has a malicious value ... |
| CVE-2024-8860 | MEDIUM | 4.3 | 0.2% | Aug 26, 2025 | The Tourfic plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2024-46413 | MEDIUM | 5.1 | 0.3% | Aug 25, 2025 | Rebuild v3.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the type parameter in the com.rebuild.... |
| CVE-2024-46412 | MEDIUM | 6.5 | 0.4% | Aug 25, 2025 | Incorrect access control in the prehandle function of Rebuild v3.7.7 allows attackers to bypass authentication via a cra... |
| CVE-2024-39923 | MEDIUM | 6.1 | 0.2% | Aug 25, 2025 | An issue was discovered in Mahara 24.04 before 24.04.2 and 23.04 before 23.04.7. The About, Contact, and Help footer lin... |
| CVE-2024-48988 | HIGH | 7.6 | 0.6% | Aug 22, 2025 | SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users... |
| CVE-2024-53499 | CRITICAL | 9.8 | 0.5% | Aug 22, 2025 | Jeewms v3.7 was discovered to contain a SQL injection vulnerability via the CgReportController API. |
| CVE-2024-53496 | CRITICAL | 9.8 | 0.5% | Aug 22, 2025 | Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive compone... |
| CVE-2024-52786 | CRITICAL | 9.8 | 0.8% | Aug 22, 2025 | An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute a... |
| CVE-2024-50645 | CRITICAL | 9.8 | 0.6% | Aug 22, 2025 | MallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access ... |
| CVE-2024-53494 | HIGH | 7.5 | 0.3% | Aug 22, 2025 | Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive compone... |
| CVE-2024-50644 | CRITICAL | 9.8 | 0.5% | Aug 22, 2025 | zhisheng17 blog 3.0.1-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to... |
| CVE-2024-58239 | MEDIUM | 5.5 | 0.2% | Aug 22, 2025 | In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us... |
| CVE-2024-56179 | HIGH | 7.8 | 0.4% | Aug 22, 2025 | In MindManager Windows versions prior to 24.1.150, attackers could potentially write to unexpected directories in victim... |
| CVE-2024-50641 | HIGH | 8.1 | 0.4% | Aug 21, 2025 | An authentication bypass vulnerability in PandoraNext-TokensTool v0.6.8 and before. An attacker can exploit this vulnera... |
| CVE-2024-45438 | CRITICAL | 9.1 | 0.5% | Aug 21, 2025 | An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. Th... |
| CVE-2024-57155 | CRITICAL | 9.8 | 0.4% | Aug 20, 2025 | Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access sensitive APIs without a t... |
| CVE-2024-57154 | CRITICAL | 9.8 | 0.4% | Aug 20, 2025 | Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted pay... |
| CVE-2024-57152 | HIGH | 7.5 | 0.3% | Aug 20, 2025 | Incorrect access control in the preHandle function of my-site v1.0.2 allows attackers to access sensitive components wit... |
| CVE-2024-53495 | HIGH | 7.5 | 0.3% | Aug 20, 2025 | Incorrect access control in the preHandle function of my-site v1.0.2.RELEASE allows attackers to access sensitive compon... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now