2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-43863 | MEDIUM | 5.5 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix a deadlock in dma buf fence polling... |
| CVE-2024-43862 | MEDIUM | 5.5 | 0.1% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: wan: fsl_qmc_hdlc: Convert carrier_lock spinlo... |
| CVE-2024-43861 | MEDIUM | 5.5 | 0.2% | Aug 20, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: usb: qmi_wwan: fix memory leak for not ip pack... |
| CVE-2024-43396 | MEDIUM | 5.4 | 0.5% | Aug 20, 2024 | Khoj is an application that creates personal AI agents. The Automation feature allows a user to insert arbitrary HTML in... |
| CVE-2024-41658 | MEDIUM | 6.1 | 0.4% | Aug 20, 2024 | Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earl... |
| CVE-2024-7711 | MEDIUM | 4.3 | 0.5% | Aug 20, 2024 | An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the ... |
| CVE-2024-6337 | MEDIUM | 6.5 | 0.7% | Aug 20, 2024 | An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only ... |
| CVE-2024-41773 | MEDIUM | 6.5 | 0.3% | Aug 20, 2024 | IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due t... |
| CVE-2024-6322 | MEDIUM | 5.4 | 0.3% | Aug 20, 2024 | Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user... |
| CVE-2024-43408 | MEDIUM | 6.3 | 0.2% | Aug 20, 2024 | Discourse Placeholder Forms will let you build dynamic documentation. Unsanitized and stored user input was injected in ... |
| CVE-2024-42598 | MEDIUM | 6.7 | 1.2% | Aug 20, 2024 | SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplay... |
| CVE-2024-40743 | MEDIUM | 6.1 | 0.3% | Aug 20, 2024 | The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors. |
| CVE-2024-27186 | MEDIUM | 6.1 | 0.3% | Aug 20, 2024 | The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions. |
| CVE-2024-27184 | MEDIUM | 6.1 | 0.2% | Aug 20, 2024 | Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.. |
| CVE-2024-43409 | MEDIUM | 6.5 | 0.3% | Aug 20, 2024 | Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would al... |
| CVE-2024-43397 | MEDIUM | 4.3 | 0.3% | Aug 20, 2024 | Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that al... |
| CVE-2024-43377 | MEDIUM | 4.3 | 0.2% | Aug 20, 2024 | Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1.... |
| CVE-2024-43376 | MEDIUM | 5.3 | 0.4% | Aug 20, 2024 | Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is... |
| CVE-2024-42369 | MEDIUM | 5.3 | 0.5% | Aug 20, 2024 | matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room o... |
| CVE-2024-6379 | MEDIUM | 6.1 | 0.2% | Aug 20, 2024 | A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release... |
| CVE-2024-6378 | MEDIUM | 5.4 | 0.3% | Aug 20, 2024 | A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEX... |
| CVE-2024-6377 | MEDIUM | 6.1 | 0.3% | Aug 20, 2024 | An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPER... |
| CVE-2024-39094 | MEDIUM | 5.4 | 0.3% | Aug 20, 2024 | Friendica 2024.03 is vulnerable to Cross Site Scripting (XSS) in settings/profile via the homepage, xmpp, and matrix par... |
| CVE-2024-42560 | MEDIUM | 6.1 | 0.4% | Aug 20, 2024 | A cross-site scripting (XSS) vulnerability in the component update_page_details.php of Blood Bank And Donation Managemen... |
| CVE-2024-42335 | MEDIUM | 5.4 | 0.3% | Aug 20, 2024 | 7Twenty - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now