2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7110 | MEDIUM | 6.4 | 0.3% | Aug 22, 2024 | An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prio... |
| CVE-2024-6502 | MEDIUM | 6.5 | 0.3% | Aug 22, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prio... |
| CVE-2024-45193 | MEDIUM | 4.3 | 0.3% | Aug 22, 2024 | An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validati... |
| CVE-2024-45192 | MEDIUM | 5.3 | 0.5% | Aug 22, 2024 | An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decodi... |
| CVE-2024-45191 | MEDIUM | 5.3 | 0.5% | Aug 22, 2024 | An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks du... |
| CVE-2024-43780 | MEDIUM | 4.3 | 0.3% | Aug 22, 2024 | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a gu... |
| CVE-2024-42771 | MEDIUM | 4.8 | 0.4% | Aug 22, 2024 | A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel... |
| CVE-2024-42770 | MEDIUM | 4.7 | 0.5% | Aug 22, 2024 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management Sys... |
| CVE-2024-42769 | MEDIUM | 6.1 | 0.4% | Aug 22, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management... |
| CVE-2024-42497 | MEDIUM | 4.9 | 0.3% | Aug 22, 2024 | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permission... |
| CVE-2024-3127 | MEDIUM | 4.3 | 0.3% | Aug 22, 2024 | An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting... |
| CVE-2024-36441 | MEDIUM | 5.4 | 0.3% | Aug 22, 2024 | Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to ope... |
| CVE-2024-43787 | MEDIUM | 5 | 0.2% | Aug 22, 2024 | Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypass... |
| CVE-2024-43398 | MEDIUM | 5.9 | 1.2% | Aug 22, 2024 | REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many... |
| CVE-2024-36440 | MEDIUM | 6.8 | 0.3% | Aug 22, 2024 | An issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may ... |
| CVE-2024-7848 | MEDIUM | 6.5 | 0.3% | Aug 22, 2024 | The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Refe... |
| CVE-2024-39746 | MEDIUM | 5.9 | 0.3% | Aug 22, 2024 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive inform... |
| CVE-2024-39744 | MEDIUM | 4.3 | 0.2% | Aug 22, 2024 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 is vulnerable to cross-site request forgery which could ... |
| CVE-2024-35151 | MEDIUM | 6.5 | 0.4% | Aug 22, 2024 | IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper a... |
| CVE-2024-7778 | MEDIUM | 5.4 | 0.3% | Aug 22, 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all... |
| CVE-2024-6870 | MEDIUM | 5.4 | 0.3% | Aug 22, 2024 | The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in ... |
| CVE-2024-8072 | MEDIUM | 5.3 | 0.6% | Aug 22, 2024 | Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users |
| CVE-2024-43813 | MEDIUM | 4.3 | 0.2% | Aug 22, 2024 | Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticat... |
| CVE-2024-42411 | MEDIUM | 5.3 | 0.3% | Aug 22, 2024 | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST ... |
| CVE-2024-39836 | MEDIUM | 6.5 | 0.3% | Aug 22, 2024 | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synt... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now