2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39624 | HIGH | 8.8 | 0.5% | Aug 1, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro ... |
| CVE-2024-39621 | HIGH | 7.2 | 0.5% | Aug 1, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro ... |
| CVE-2024-38791 | HIGH | 7.1 | 0.2% | Aug 1, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request For... |
| CVE-2024-38775 | HIGH | 7.2 | 0.6% | Aug 1, 2024 | Improper Privilege Management vulnerability in WebAppick CTX Feed allows Privilege Escalation.This issue affects CTX Fee... |
| CVE-2024-38768 | HIGH | 8.8 | 0.5% | Aug 1, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Webangon The Pack Elemen... |
| CVE-2024-38746 | HIGH | 7.1 | 0.5% | Aug 1, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MakeStories Team MakeSto... |
| CVE-2024-32864 | HIGH | 8.1 | 0.2% | Aug 1, 2024 | Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS) |
| CVE-2024-32863 | HIGH | 8.8 | 0.2% | Aug 1, 2024 | Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF) |
| CVE-2024-7360 | HIGH | 8.8 | 0.3% | Aug 1, 2024 | A vulnerability classified as problematic has been found in SourceCodester Tracking Monitoring Management System 1.0. Th... |
| CVE-2024-7256 | HIGH | 8.8 | 0.5% | Aug 1, 2024 | Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to exe... |
| CVE-2024-7255 | HIGH | 8.8 | 0.7% | Aug 1, 2024 | Out of bounds read in WebTransport in Google Chrome prior to 127.0.6533.88 allowed a remote attacker to potentially perf... |
| CVE-2024-6990 | HIGH | 8.8 | 0.9% | Aug 1, 2024 | Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially pe... |
| CVE-2024-6873 | HIGH | 8.1 | 0.7% | Aug 1, 2024 | It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector b... |
| CVE-2024-6242 | HIGH | 7.3 | 9.2% | Aug 1, 2024 | A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot f... |
| CVE-2024-6040 | HIGH | 8.8 | 0.2% | Aug 1, 2024 | In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multi... |
| CVE-2024-41265 | HIGH | 7.5 | 0.3% | Aug 1, 2024 | A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via t... |
| CVE-2024-41264 | HIGH | 7.5 | 0.5% | Aug 1, 2024 | An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostK... |
| CVE-2024-41260 | HIGH | 7.5 | 0.5% | Aug 1, 2024 | A static initialization vector (IV) in the encrypt function of netbird management's service from v0.23.2 to v0.29.1 allo... |
| CVE-2024-41946 | HIGH | 7.5 | 1.2% | Aug 1, 2024 | REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity... |
| CVE-2024-41144 | HIGH | 7.1 | 0.4% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced post... |
| CVE-2024-41123 | HIGH | 7.5 | 1.3% | Aug 1, 2024 | REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has... |
| CVE-2024-39832 | HIGH | 8.7 | 0.5% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error h... |
| CVE-2024-7358 | HIGH | 8.5 | 0.2% | Aug 1, 2024 | A vulnerability was found in Point B Ltd Getscreen Agent 2.19.6 on Windows. It has been declared as critical. Affected b... |
| CVE-2024-28972 | HIGH | 7.5 | 0.3% | Aug 1, 2024 | Dell InsightIQ, Verion 5.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthentica... |
| CVE-2024-6529 | HIGH | 7.1 | 0.9% | Aug 1, 2024 | The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now