2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37961 | HIGH | 7.1 | 0.3% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in codoc.Jp al... |
| CVE-2024-6281 | HIGH | 7.3 | 0.3% | Jul 20, 2024 | A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `... |
| CVE-2024-40348 | HIGH | 8.2 | 8.3% | Jul 20, 2024 | An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory... |
| CVE-2024-41122 | HIGH | 8.8 | 0.6% | Jul 19, 2024 | Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can t... |
| CVE-2024-41121 | HIGH | 8.8 | 0.7% | Jul 19, 2024 | Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can t... |
| CVE-2024-39906 | HIGH | 8.3 | 1.0% | Jul 19, 2024 | A command injection vulnerability was found in the IndieAuth functionality of the Ruby on Rails based Haven blog web app... |
| CVE-2024-40400 | HIGH | 8.8 | 0.8% | Jul 19, 2024 | An arbitrary file upload vulnerability in the image upload function of Automad v2.0.0 allows attackers to execute arbitr... |
| CVE-2024-41600 | HIGH | 7.5 | 0.4% | Jul 19, 2024 | Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive... |
| CVE-2024-41602 | HIGH | 8.8 | 0.2% | Jul 19, 2024 | Cross Site Request Forgery vulnerability in Spina CMS v.2.18.0 and before allows a remote attacker to escalate privilege... |
| CVE-2024-41601 | HIGH | 7.5 | 0.5% | Jul 19, 2024 | Insecure Permissions vulnerability in lin-CMS v.0.2.0 and before allows a remote attacker to obtain sensitive informatio... |
| CVE-2024-41492 | HIGH | 7.5 | 0.6% | Jul 19, 2024 | A stack overflow in Tenda AX1806 v1.0.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. |
| CVE-2024-41281 | HIGH | 8.8 | 0.3% | Jul 19, 2024 | Linksys WRT54G v4.21.5 has a stack overflow vulnerability in get_merge_mac function. |
| CVE-2024-39963 | HIGH | 8 | 1.5% | Jul 19, 2024 | AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01... |
| CVE-2024-27489 | HIGH | 7.5 | 0.4% | Jul 19, 2024 | An issue in the DelFile() function of WMCMS v4.4 allows attackers to delete arbitrary files via a crafted POST request. |
| CVE-2024-37066 | HIGH | 8.8 | 1.8% | Jul 19, 2024 | A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to ... |
| CVE-2024-41107 | HIGH | 8.1 | 17.8% | Jul 19, 2024 | The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments wh... |
| CVE-2024-6906 | HIGH | 8.8 | 0.5% | Jul 19, 2024 | A vulnerability was found in SourceCodester Record Management System 1.0 and classified as critical. This issue affects ... |
| CVE-2024-6905 | HIGH | 8.8 | 0.6% | Jul 19, 2024 | A vulnerability has been found in SourceCodester Record Management System 1.0 and classified as critical. This vulnerabi... |
| CVE-2024-6904 | HIGH | 8.8 | 0.5% | Jul 19, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Record Management System 1.0. This affect... |
| CVE-2024-41172 | HIGH | 7.5 | 1.2% | Jul 19, 2024 | In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit ... |
| CVE-2024-32007 | HIGH | 7.5 | 1.3% | Jul 19, 2024 | An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an at... |
| CVE-2024-6903 | HIGH | 8.8 | 0.5% | Jul 19, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Record Management System 1.0. Affect... |
| CVE-2024-6902 | HIGH | 8.8 | 0.5% | Jul 19, 2024 | A vulnerability classified as critical was found in SourceCodester Record Management System 1.0. Affected by this vulner... |
| CVE-2024-6338 | HIGH | 8.8 | 0.5% | Jul 19, 2024 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ paramete... |
| CVE-2024-40724 | HIGH | 7.8 | 0.3% | Jul 19, 2024 | Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.2 allows a local attacker to execute arbitrary ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now