2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41843 | MEDIUM | 5.4 | 0.3% | Aug 23, 2024 | Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-41842 | MEDIUM | 4.8 | 0.3% | Aug 23, 2024 | Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-41841 | MEDIUM | 5.4 | 0.3% | Aug 23, 2024 | Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2024-43032 | MEDIUM | 4.3 | 0.2% | Aug 23, 2024 | autMan v2.9.6 allows attackers to bypass authentication via a crafted web request. |
| CVE-2024-43031 | MEDIUM | 4.3 | 0.2% | Aug 23, 2024 | autMan v2.9.6 was discovered to contain an access control issue. |
| CVE-2024-42364 | MEDIUM | 6.5 | 0.2% | Aug 23, 2024 | Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1... |
| CVE-2024-8113 | MEDIUM | 5.4 | 0.3% | Aug 23, 2024 | Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tag... |
| CVE-2024-8112 | MEDIUM | 6.1 | 0.5% | Aug 23, 2024 | A vulnerability was found in thinkgem JeeSite 5.3. It has been rated as problematic. This issue affects some unknown pro... |
| CVE-2024-42766 | MEDIUM | 5.4 | 0.3% | Aug 23, 2024 | Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php. |
| CVE-2024-41150 | MEDIUM | 6.1 | 1.2% | Aug 23, 2024 | An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDe... |
| CVE-2024-38869 | MEDIUM | 5.4 | 1.0% | Aug 23, 2024 | Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configu... |
| CVE-2024-5502 | MEDIUM | 5.4 | 0.3% | Aug 23, 2024 | The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Imag... |
| CVE-2024-38807 | MEDIUM | 6.3 | 0.1% | Aug 23, 2024 | Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature v... |
| CVE-2024-43105 | MEDIUM | 4.3 | 0.4% | Aug 23, 2024 | Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a... |
| CVE-2024-6715 | MEDIUM | 6.1 | 0.3% | Aug 23, 2024 | The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerabil... |
| CVE-2024-3282 | MEDIUM | 4.8 | 0.3% | Aug 23, 2024 | The WP Table Builder WordPress plugin through 1.5.0 does not sanitise and escape some of its Table data, which could al... |
| CVE-2024-38208 | MEDIUM | 6.1 | 0.4% | Aug 22, 2024 | Microsoft Edge for Android Spoofing Vulnerability |
| CVE-2024-8084 | MEDIUM | 4.8 | 0.4% | Aug 22, 2024 | A vulnerability, which was classified as problematic, was found in SourceCodester Online Computer and Laptop Store 1.0. ... |
| CVE-2024-43790 | MEDIUM | 5.5 | 0.3% | Aug 22, 2024 | Vim is an open source command line text editor. When performing a search and displaying the search-count message is disa... |
| CVE-2024-42763 | MEDIUM | 5.4 | 0.4% | Aug 22, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in the "/schedule.php" page of the Kashipara Bus Ticket R... |
| CVE-2024-42762 | MEDIUM | 5.4 | 0.4% | Aug 22, 2024 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/history.php" in Kashipara Bus Ticket Reservation System... |
| CVE-2024-42761 | MEDIUM | 6.1 | 0.4% | Aug 22, 2024 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin_schedule.php" in Kashipara Bus Ticket Reservation... |
| CVE-2024-7634 | MEDIUM | 4.9 | 0.5% | Aug 22, 2024 | NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwri... |
| CVE-2024-42768 | MEDIUM | 6.8 | 0.2% | Aug 22, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_... |
| CVE-2024-8041 | MEDIUM | 6.5 | 0.5% | Aug 22, 2024 | A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now