2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-40722 | MEDIUM | 4.3 | 0.5% | Aug 2, 2024 | The specific API in TCBServiSign Windows Version from CHANGING Information Technology does does not properly validate th... |
| CVE-2024-38878 | MEDIUM | 6.5 | 11.5% | Aug 2, 2024 | A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (A... |
| CVE-2024-4643 | MEDIUM | 5.4 | 0.4% | Aug 2, 2024 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W... |
| CVE-2024-40719 | MEDIUM | 6.5 | 0.2% | Aug 2, 2024 | The encryption strength of the authorization keys in CHANGING Information Technology TCBServiSign Windows Version is ins... |
| CVE-2024-27182 | MEDIUM | 4.9 | 0.7% | Aug 2, 2024 | In Apache Linkis <= 1.5.0, Arbitrary file deletion in Basic management services on A user with an administrator accou... |
| CVE-2024-42460 | MEDIUM | 5.3 | 0.5% | Aug 2, 2024 | In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whet... |
| CVE-2024-42459 | MEDIUM | 5.3 | 0.3% | Aug 2, 2024 | In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature leng... |
| CVE-2024-39396 | MEDIUM | 5.5 | 0.2% | Aug 2, 2024 | InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by an out-of-bounds read vulnerability that could le... |
| CVE-2024-5595 | MEDIUM | 5.4 | 0.4% | Aug 2, 2024 | The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before output... |
| CVE-2024-3827 | MEDIUM | 5.4 | 0.3% | Aug 2, 2024 | The Spectra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block ids in all versions up to, a... |
| CVE-2024-6567 | MEDIUM | 5.3 | 0.4% | Aug 2, 2024 | The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.8001.... |
| CVE-2024-22278 | MEDIUM | 4.3 | 0.4% | Aug 2, 2024 | Incorrect user permission validation in Harbor <v2.9.5 and Harbor <v2.10.3 allows authenticated users to modify configur... |
| CVE-2024-39647 | MEDIUM | 6.1 | 0.3% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kofi Mokome Messag... |
| CVE-2024-39646 | MEDIUM | 6.1 | 0.6% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kunal Custom 404 P... |
| CVE-2024-39644 | MEDIUM | 5.4 | 0.2% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Modernaweb ... |
| CVE-2024-39643 | MEDIUM | 6.1 | 0.3% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Registratio... |
| CVE-2024-39631 | MEDIUM | 6.1 | 0.3% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wasiliy Strecker /... |
| CVE-2024-39629 | MEDIUM | 4.8 | 0.2% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeGrill ... |
| CVE-2024-39627 | MEDIUM | 4.8 | 0.3% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Imagely Nex... |
| CVE-2024-39626 | MEDIUM | 4.8 | 0.2% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rob @ 5 Star Plugi... |
| CVE-2024-7368 | MEDIUM | 5.4 | 0.4% | Aug 1, 2024 | A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as problematic. This vul... |
| CVE-2024-41965 | MEDIUM | 4.2 | 0.3% | Aug 1, 2024 | Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a bu... |
| CVE-2024-41957 | MEDIUM | 5.3 | 0.4% | Aug 1, 2024 | Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a windo... |
| CVE-2024-41949 | MEDIUM | 6.4 | 0.2% | Aug 1, 2024 | biscuit-rust is the Rust implementation of Biscuit, an authentication and authorization token for microservices architec... |
| CVE-2024-41948 | MEDIUM | 5 | 0.3% | Aug 1, 2024 | biscuit-java is the java implementation of Biscuit, an authentication and authorization token for microservices architec... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now