2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39810 | MEDIUM | 4.9 | 0.5% | Aug 22, 2024 | Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the Elasti... |
| CVE-2024-45165 | MEDIUM | 5.3 | 0.2% | Aug 22, 2024 | An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with e... |
| CVE-2024-7836 | MEDIUM | 4.3 | 0.3% | Aug 22, 2024 | The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the dup... |
| CVE-2024-5583 | MEDIUM | 5.4 | 0.2% | Aug 22, 2024 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre... |
| CVE-2024-42056 | MEDIUM | 6.5 | 0.2% | Aug 22, 2024 | Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials f... |
| CVE-2024-8035 | MEDIUM | 4.3 | 0.3% | Aug 21, 2024 | Inappropriate implementation in Extensions in Google Chrome on Windows prior to 128.0.6613.84 allowed a remote attacker ... |
| CVE-2024-8034 | MEDIUM | 4.3 | 0.4% | Aug 21, 2024 | Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker... |
| CVE-2024-8033 | MEDIUM | 4.3 | 0.3% | Aug 21, 2024 | Inappropriate implementation in WebApp Installs in Google Chrome on Windows prior to 128.0.6613.84 allowed an attacker w... |
| CVE-2024-7981 | MEDIUM | 4.3 | 0.4% | Aug 21, 2024 | Inappropriate implementation in Views in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI sp... |
| CVE-2024-7978 | MEDIUM | 4.3 | 0.4% | Aug 21, 2024 | Insufficient policy enforcement in Data Transfer in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who c... |
| CVE-2024-7976 | MEDIUM | 4.3 | 0.4% | Aug 21, 2024 | Inappropriate implementation in FedCM in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform UI sp... |
| CVE-2024-7975 | MEDIUM | 4.3 | 0.4% | Aug 21, 2024 | Inappropriate implementation in Permissions in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform... |
| CVE-2024-20466 | MEDIUM | 4.9 | 0.5% | Aug 21, 2024 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2024-41572 | MEDIUM | 6.1 | 0.3% | Aug 21, 2024 | Learning with Texts (LWT) 2.0.3 is vulnerable to Cross Site Scripting (XSS). The application has a specific function tha... |
| CVE-2024-20488 | MEDIUM | 6.1 | 0.3% | Aug 21, 2024 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni... |
| CVE-2024-42550 | MEDIUM | 5.4 | 0.2% | Aug 21, 2024 | A cross-site scripting (XSS) vulnerability in the component /email/welcome.php of Mini Inventory and Sales Management Sy... |
| CVE-2024-7722 | MEDIUM | 4.3 | 0.6% | Aug 21, 2024 | Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attack... |
| CVE-2024-7602 | MEDIUM | 6.5 | 2.4% | Aug 21, 2024 | Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remo... |
| CVE-2024-41937 | MEDIUM | 6.1 | 1.8% | Aug 21, 2024 | Apache Airflow, versions before 2.10.0, have a vulnerability that allows the developer of a malicious provider to execut... |
| CVE-2024-43407 | MEDIUM | 6.1 | 0.4% | Aug 21, 2024 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A potential vulnerability has been discovered in C... |
| CVE-2024-43371 | MEDIUM | 6.5 | 0.3% | Aug 21, 2024 | CKAN is an open-source data management system for powering data hubs and data portals. There are a number of CKAN plugin... |
| CVE-2024-41675 | MEDIUM | 6.1 | 0.4% | Aug 21, 2024 | CKAN is an open-source data management system for powering data hubs and data portals. The Datatables view plugin did no... |
| CVE-2024-41674 | MEDIUM | 5.3 | 0.4% | Aug 21, 2024 | CKAN is an open-source data management system for powering data hubs and data portals. If there were connection issues w... |
| CVE-2024-6339 | MEDIUM | 6.1 | 0.4% | Aug 21, 2024 | The Phlox PRO theme for WordPress is vulnerable to Reflected Cross-Site Scripting via search parameters in all versions ... |
| CVE-2024-7647 | MEDIUM | 6.1 | 0.2% | Aug 21, 2024 | The OTA Sync Booking Engine Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now