2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42475 | MEDIUM | 6.5 | 0.2% | Aug 15, 2024 | In the OAuth library for nim prior to version 0.11, the `state` values generated by the `generateState` function do not ... |
| CVE-2024-27731 | MEDIUM | 6.1 | 0.3% | Aug 15, 2024 | Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via t... |
| CVE-2024-27729 | MEDIUM | 6.1 | 0.4% | Aug 15, 2024 | Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via t... |
| CVE-2024-27728 | MEDIUM | 6.1 | 0.3% | Aug 15, 2024 | Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via t... |
| CVE-2024-25633 | MEDIUM | 5.4 | 0.2% | Aug 15, 2024 | eLabFTW is an open source electronic lab notebook for research labs. In an eLabFTW system, one can configure who is allo... |
| CVE-2024-32231 | MEDIUM | 6.3 | 1.2% | Aug 15, 2024 | Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter. |
| CVE-2024-22219 | MEDIUM | 6.3 | 0.5% | Aug 15, 2024 | XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows... |
| CVE-2024-22217 | MEDIUM | 6.5 | 0.3% | Aug 15, 2024 | A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use speci... |
| CVE-2024-40705 | MEDIUM | 6.5 | 0.6% | Aug 15, 2024 | IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted ... |
| CVE-2024-40704 | MEDIUM | 4.9 | 0.6% | Aug 15, 2024 | IBM InfoSphere Information Server 11.7 could allow a privileged user to obtain sensitive information from authentication... |
| CVE-2024-31905 | MEDIUM | 5.9 | 0.3% | Aug 15, 2024 | IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failu... |
| CVE-2024-31800 | MEDIUM | 6.8 | 0.4% | Aug 15, 2024 | Authentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privi... |
| CVE-2024-31799 | MEDIUM | 4.6 | 0.3% | Aug 15, 2024 | Information Disclosure in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to read the Wi... |
| CVE-2024-31798 | MEDIUM | 6.8 | 0.4% | Aug 15, 2024 | Identical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with phy... |
| CVE-2024-6347 | MEDIUM | 6.5 | 0.3% | Aug 15, 2024 | * Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Alti... |
| CVE-2024-42680 | MEDIUM | 5.5 | 0.3% | Aug 15, 2024 | An issue in Super easy enterprise management system v.1.0.0 and before allows a local attacker to obtain the server abso... |
| CVE-2024-42678 | MEDIUM | 6.1 | 0.3% | Aug 15, 2024 | Cross Site Scripting vulnerability in Super easy enterprise management system v.1.0.0 and before allows a local attacker... |
| CVE-2024-42677 | MEDIUM | 5.5 | 0.3% | Aug 15, 2024 | An issue in Huizhi enterprise resource management system v.1.0 and before allows a local attacker to obtain sensitive in... |
| CVE-2024-7411 | MEDIUM | 5.3 | 0.4% | Aug 15, 2024 | The Newsletters plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 4.9.9. ... |
| CVE-2024-7064 | MEDIUM | 5.4 | 0.3% | Aug 15, 2024 | The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all vers... |
| CVE-2024-7063 | MEDIUM | 4.3 | 0.4% | Aug 15, 2024 | The ElementsKit Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl... |
| CVE-2024-7815 | MEDIUM | 4.8 | 1.1% | Aug 15, 2024 | A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. Affecte... |
| CVE-2024-7814 | MEDIUM | 4.8 | 0.4% | Aug 15, 2024 | A vulnerability, which was classified as problematic, was found in CodeAstro Online Railway Reservation System 1.0. Affe... |
| CVE-2024-6534 | MEDIUM | 4.3 | 0.3% | Aug 15, 2024 | Directus v10.13.0 allows an authenticated external attacker to modify presets created by the same user to assign them to... |
| CVE-2024-7812 | MEDIUM | 5.4 | 0.4% | Aug 15, 2024 | A vulnerability classified as problematic was found in SourceCodester Best House Rental Management System 1.0. This vuln... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now