2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42397 | MEDIUM | 5.3 | 0.3% | Aug 6, 2024 | Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed ... |
| CVE-2024-42396 | MEDIUM | 5.3 | 0.3% | Aug 6, 2024 | Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed ... |
| CVE-2024-42347 | MEDIUM | 6.5 | 0.4% | Aug 6, 2024 | matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver c... |
| CVE-2024-41677 | MEDIUM | 6.1 | 0.5% | Aug 6, 2024 | Qwik is a performance focused javascript framework. A potential mutation XSS vulnerability exists in Qwik for versions u... |
| CVE-2024-42358 | MEDIUM | 5.5 | 0.3% | Aug 6, 2024 | PDFio is a simple C library for reading and writing PDF files. There is a denial of service (DOS) vulnerability in the T... |
| CVE-2024-39229 | MEDIUM | 5.3 | 0.2% | Aug 6, 2024 | An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT... |
| CVE-2024-7564 | MEDIUM | 6.5 | 1.2% | Aug 6, 2024 | Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remo... |
| CVE-2024-7005 | MEDIUM | 4.3 | 0.4% | Aug 6, 2024 | Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote att... |
| CVE-2024-7004 | MEDIUM | 4.3 | 0.4% | Aug 6, 2024 | Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote att... |
| CVE-2024-7003 | MEDIUM | 4.3 | 0.4% | Aug 6, 2024 | Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a ... |
| CVE-2024-7001 | MEDIUM | 4.3 | 0.4% | Aug 6, 2024 | Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a u... |
| CVE-2024-6999 | MEDIUM | 4.3 | 0.4% | Aug 6, 2024 | Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a ... |
| CVE-2024-6995 | MEDIUM | 4.7 | 0.5% | Aug 6, 2024 | Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker ... |
| CVE-2024-43113 | MEDIUM | 6.1 | 0.3% | Aug 6, 2024 | The contextual menu for links could provide an opportunity for cross-site scripting attacks This vulnerability affects F... |
| CVE-2024-43112 | MEDIUM | 6.1 | 0.3% | Aug 6, 2024 | Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects F... |
| CVE-2024-43111 | MEDIUM | 6.1 | 0.3% | Aug 6, 2024 | Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vuln... |
| CVE-2024-41333 | MEDIUM | 6.1 | 0.5% | Aug 6, 2024 | A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to ex... |
| CVE-2024-39751 | MEDIUM | 4.3 | 0.4% | Aug 6, 2024 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec... |
| CVE-2024-23464 | MEDIUM | 4.9 | 0.4% | Aug 6, 2024 | In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Z... |
| CVE-2024-36424 | MEDIUM | 5.5 | 1.0% | Aug 6, 2024 | K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of ... |
| CVE-2024-41911 | MEDIUM | 5.4 | 0.2% | Aug 6, 2024 | A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not... |
| CVE-2024-41910 | MEDIUM | 6.1 | 0.3% | Aug 6, 2024 | A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware con... |
| CVE-2024-40101 | MEDIUM | 6.1 | 0.9% | Aug 6, 2024 | A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unaut... |
| CVE-2024-7551 | MEDIUM | 4.9 | 0.9% | Aug 6, 2024 | A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as problematic. Affected is an unknown func... |
| CVE-2024-7531 | MEDIUM | 6.5 | 0.4% | Aug 6, 2024 | Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now