2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38214 | MEDIUM | 6.5 | 1.5% | Aug 13, 2024 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
| CVE-2024-38213 | MEDIUM | 6.5 | 13.4% | Aug 13, 2024 | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2024-38197 | MEDIUM | 6.5 | 15.9% | Aug 13, 2024 | Microsoft Teams for iOS Spoofing Vulnerability |
| CVE-2024-38173 | MEDIUM | 6.7 | 0.7% | Aug 13, 2024 | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2024-38167 | MEDIUM | 6.5 | 1.3% | Aug 13, 2024 | .NET and Visual Studio Information Disclosure Vulnerability |
| CVE-2024-38165 | MEDIUM | 6.5 | 1.3% | Aug 13, 2024 | Windows Compressed Folder Tampering Vulnerability |
| CVE-2024-38161 | MEDIUM | 6.8 | 0.8% | Aug 13, 2024 | Windows Mobile Broadband Driver Remote Code Execution Vulnerability |
| CVE-2024-38155 | MEDIUM | 5.5 | 0.7% | Aug 13, 2024 | Security Center Broker Information Disclosure Vulnerability |
| CVE-2024-38151 | MEDIUM | 5.5 | 0.6% | Aug 13, 2024 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2024-38143 | MEDIUM | 4.2 | 1.7% | Aug 13, 2024 | Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability |
| CVE-2024-38123 | MEDIUM | 4.4 | 0.7% | Aug 13, 2024 | Windows Bluetooth Driver Information Disclosure Vulnerability |
| CVE-2024-38122 | MEDIUM | 5.5 | 0.6% | Aug 13, 2024 | Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability |
| CVE-2024-38118 | MEDIUM | 5.5 | 0.6% | Aug 13, 2024 | Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability |
| CVE-2024-41711 | MEDIUM | 6.8 | 0.5% | Aug 13, 2024 | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, ... |
| CVE-2024-41614 | MEDIUM | 4.8 | 0.3% | Aug 13, 2024 | symphonycms <=2.7.10 is vulnerable to Cross Site Scripting (XSS) in the Comment component for articles. |
| CVE-2024-41613 | MEDIUM | 5.4 | 0.4% | Aug 13, 2024 | A Cross Site Scripting (XSS) vulnerability in Symphony CMS 2.7.10 allows remote attackers to inject arbitrary web script... |
| CVE-2024-21981 | MEDIUM | 5.7 | 0.1% | Aug 13, 2024 | Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrar... |
| CVE-2024-36505 | MEDIUM | 5.5 | 0.2% | Aug 13, 2024 | An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7... |
| CVE-2024-6384 | MEDIUM | 5.3 | 0.4% | Aug 13, 2024 | "Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifi... |
| CVE-2024-42740 | MEDIUM | 6.8 | 2.8% | Aug 13, 2024 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability... |
| CVE-2024-3913 | MEDIUM | 5.9 | 0.5% | Aug 13, 2024 | An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable... |
| CVE-2024-38501 | MEDIUM | 6.1 | 0.3% | Aug 13, 2024 | An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML c... |
| CVE-2024-43165 | MEDIUM | 6.5 | 0.6% | Aug 13, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rashid87 WPSection allow... |
| CVE-2024-41774 | MEDIUM | 4.8 | 0.2% | Aug 13, 2024 | IBM Common Licensing 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to em... |
| CVE-2024-39642 | MEDIUM | 6.5 | 0.4% | Aug 13, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Accessing Functionality No... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now