2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42164 | MEDIUM | 4.3 | 0.4% | Aug 12, 2024 | Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two... |
| CVE-2024-41890 | MEDIUM | 5.3 | 1.1% | Aug 12, 2024 | Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: ... |
| CVE-2024-41888 | MEDIUM | 5.3 | 1.2% | Aug 12, 2024 | Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: ... |
| CVE-2024-41482 | MEDIUM | 6.1 | 0.3% | Aug 12, 2024 | Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component. |
| CVE-2024-41481 | MEDIUM | 6.1 | 0.4% | Aug 12, 2024 | Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component. |
| CVE-2024-41332 | MEDIUM | 6.5 | 0.6% | Aug 12, 2024 | Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 al... |
| CVE-2024-40484 | MEDIUM | 6.1 | 0.6% | Aug 12, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in "/oahms/search.php" in PHPGurukul Old Age Home Managem... |
| CVE-2024-40481 | MEDIUM | 5.4 | 0.6% | Aug 12, 2024 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/view-enquiry.php" in PHPGurukul Old Age Home Mana... |
| CVE-2024-40478 | MEDIUM | 5.4 | 0.6% | Aug 12, 2024 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/afeedback.php" in Kashipara Online Exam System v1... |
| CVE-2024-40474 | MEDIUM | 5.4 | 0.5% | Aug 12, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Managem... |
| CVE-2024-40473 | MEDIUM | 5.4 | 0.6% | Aug 12, 2024 | A Stored Cross Site Scripting (XSS) vulnerability was found in "manage_houses.php" in SourceCodester Best House Rental M... |
| CVE-2024-38200 | MEDIUM | 6.5 | 19.7% | Aug 12, 2024 | Microsoft Office Spoofing Vulnerability |
| CVE-2024-37283 | MEDIUM | 6.5 | 0.6% | Aug 12, 2024 | An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the lo... |
| CVE-2024-36518 | MEDIUM | 5.4 | 3.1% | Aug 12, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface a... |
| CVE-2024-32765 | MEDIUM | 4.2 | 0.2% | Aug 12, 2024 | A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local ... |
| CVE-2024-22121 | MEDIUM | 6.1 | 0.2% | Aug 12, 2024 | A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integri... |
| CVE-2024-22114 | MEDIUM | 4.3 | 0.6% | Aug 12, 2024 | User with no permission to any of the Hosts can access and view host count & other statistics through System Information... |
| CVE-2024-21877 | MEDIUM | 6.5 | 0.8% | Aug 12, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in ... |
| CVE-2024-0115 | MEDIUM | 6.1 | 0.2% | Aug 12, 2024 | NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may caus... |
| CVE-2024-42493 | MEDIUM | 5.3 | 0.3% | Aug 8, 2024 | Dorsett Controls InfoScan is vulnerable due to a leak of possible sensitive information through the response headers an... |
| CVE-2024-7394 | MEDIUM | 4.8 | 0.4% | Aug 8, 2024 | Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName(). A rogue a... |
| CVE-2024-0102 | MEDIUM | 5.5 | 0.2% | Aug 8, 2024 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm, where an attacker can cause an out-of-bounds... |
| CVE-2024-7480 | MEDIUM | 4.4 | 0.2% | Aug 8, 2024 | An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interfa... |
| CVE-2024-7477 | MEDIUM | 6.7 | 0.2% | Aug 8, 2024 | A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privil... |
| CVE-2024-41238 | MEDIUM | 5.3 | 0.4% | Aug 8, 2024 | A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now