2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7256 | HIGH | 8.8 | 0.5% | Aug 1, 2024 | Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to exe... |
| CVE-2024-7255 | HIGH | 8.8 | 0.7% | Aug 1, 2024 | Out of bounds read in WebTransport in Google Chrome prior to 127.0.6533.88 allowed a remote attacker to potentially perf... |
| CVE-2024-6990 | HIGH | 8.8 | 0.9% | Aug 1, 2024 | Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially pe... |
| CVE-2024-6873 | HIGH | 8.1 | 0.7% | Aug 1, 2024 | It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector b... |
| CVE-2024-6242 | HIGH | 7.3 | 9.2% | Aug 1, 2024 | A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot f... |
| CVE-2024-6040 | HIGH | 8.8 | 0.2% | Aug 1, 2024 | In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multi... |
| CVE-2024-41265 | HIGH | 7.5 | 0.3% | Aug 1, 2024 | A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via t... |
| CVE-2024-41264 | HIGH | 7.5 | 0.5% | Aug 1, 2024 | An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostK... |
| CVE-2024-41260 | HIGH | 7.5 | 0.5% | Aug 1, 2024 | A static initialization vector (IV) in the encrypt function of netbird management's service from v0.23.2 to v0.29.1 allo... |
| CVE-2024-41946 | HIGH | 7.5 | 1.2% | Aug 1, 2024 | REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity... |
| CVE-2024-41144 | HIGH | 7.1 | 0.4% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced post... |
| CVE-2024-41123 | HIGH | 7.5 | 1.3% | Aug 1, 2024 | REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has... |
| CVE-2024-39832 | HIGH | 8.7 | 0.5% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error h... |
| CVE-2024-7358 | HIGH | 8.5 | 0.2% | Aug 1, 2024 | A vulnerability was found in Point B Ltd Getscreen Agent 2.19.6 on Windows. It has been declared as critical. Affected b... |
| CVE-2024-28972 | HIGH | 7.5 | 0.3% | Aug 1, 2024 | Dell InsightIQ, Verion 5.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthentica... |
| CVE-2024-6529 | HIGH | 7.1 | 0.9% | Aug 1, 2024 | The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting ... |
| CVE-2024-3983 | HIGH | 8.1 | 0.3% | Aug 1, 2024 | The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some bulk actions, which cou... |
| CVE-2024-7338 | HIGH | 8.8 | 1.2% | Aug 1, 2024 | A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the... |
| CVE-2024-6698 | HIGH | 8.8 | 0.4% | Aug 1, 2024 | The FundEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.0. T... |
| CVE-2024-7337 | HIGH | 8.8 | 1.2% | Aug 1, 2024 | A vulnerability, which was classified as critical, has been found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by... |
| CVE-2024-7336 | HIGH | 8.8 | 1.3% | Aug 1, 2024 | A vulnerability classified as critical was found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected by this vulnerability... |
| CVE-2024-7335 | HIGH | 8.8 | 1.2% | Aug 1, 2024 | A vulnerability classified as critical has been found in TOTOLINK EX200 4.0.3c.7646_B20201211. Affected is the function ... |
| CVE-2024-7334 | HIGH | 8.8 | 1.2% | Aug 1, 2024 | A vulnerability was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. It has been rated as critical. This issue affects t... |
| CVE-2024-7333 | HIGH | 8.8 | 1.2% | Aug 1, 2024 | A vulnerability was found in TOTOLINK N350RT 9.3.5u.6139_B20201216. It has been declared as critical. This vulnerability... |
| CVE-2024-6687 | HIGH | 7.5 | 0.4% | Aug 1, 2024 | The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions u... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now