2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39668 | MEDIUM | 5.4 | 0.3% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in petesheppar... |
| CVE-2024-39667 | MEDIUM | 5.4 | 0.2% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BdThemes El... |
| CVE-2024-39665 | MEDIUM | 6.5 | 0.3% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in YMC Filter ... |
| CVE-2024-39662 | MEDIUM | 5.4 | 0.3% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Modernaweb ... |
| CVE-2024-39661 | MEDIUM | 6.5 | 0.2% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ExtendTheme... |
| CVE-2024-39660 | MEDIUM | 5.9 | 0.2% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jordy Meow ... |
| CVE-2024-39659 | MEDIUM | 5.4 | 0.3% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lester ‘GaM... |
| CVE-2024-39655 | MEDIUM | 6.5 | 0.4% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LiquidPoll ... |
| CVE-2024-39652 | MEDIUM | 6.1 | 0.3% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPWeb Elite... |
| CVE-2024-39649 | MEDIUM | 5.4 | 0.3% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essent... |
| CVE-2024-39648 | MEDIUM | 4.8 | 0.3% | Aug 1, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter... |
| CVE-2024-39637 | MEDIUM | 5.4 | 0.2% | Aug 1, 2024 | Server-Side Request Forgery (SSRF) vulnerability in pixelcurve Edubin edubin.This issue affects Edubin: from n/a through... |
| CVE-2024-32931 | MEDIUM | 5.7 | 0.4% | Aug 1, 2024 | Under certain circumstances the exacqVision Web Service can expose authentication token details within communications. |
| CVE-2024-39630 | MEDIUM | 5.5 | 0.3% | Aug 1, 2024 | Deserialization of Untrusted Data vulnerability in MotoPress Timetable and Event Schedule allows Object Injection.This i... |
| CVE-2024-38772 | MEDIUM | 6.5 | 0.5% | Aug 1, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetWidgets fo... |
| CVE-2024-4353 | MEDIUM | 4.8 | 0.3% | Aug 1, 2024 | Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in the generate dashboard board ins... |
| CVE-2024-7359 | MEDIUM | 6.1 | 0.4% | Aug 1, 2024 | A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been rated as problematic.... |
| CVE-2024-7211 | MEDIUM | 6.1 | 0.2% | Aug 1, 2024 | The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulner... |
| CVE-2024-41962 | MEDIUM | 6.3 | 0.3% | Aug 1, 2024 | Bostr is an nostr relay aggregator proxy that acts like a regular nostr relay. bostr let everyone in even having authori... |
| CVE-2024-41926 | MEDIUM | 4.3 | 0.2% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the co... |
| CVE-2024-41162 | MEDIUM | 4.3 | 0.3% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification ... |
| CVE-2024-39839 | MEDIUM | 4.3 | 0.3% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their o... |
| CVE-2024-39837 | MEDIUM | 5.4 | 0.3% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious r... |
| CVE-2024-39274 | MEDIUM | 6.5 | 0.3% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the... |
| CVE-2024-36492 | MEDIUM | 6.4 | 0.3% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now