2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41943 | MEDIUM | 4.6 | 0.3% | Jul 30, 2024 | I, Librarian is an open-source version of a PDF managing SaaS. PDF notes are displayed on the Item Summary page without ... |
| CVE-2024-41305 | MEDIUM | 4.7 | 0.2% | Jul 30, 2024 | A Server-Side Request Forgery (SSRF) in the Plugins Page of WonderCMS v3.4.3 allows attackers to force the application t... |
| CVE-2024-41304 | MEDIUM | 5.4 | 0.4% | Jul 30, 2024 | An arbitrary file upload vulnerability in the uploadFileAction() function of WonderCMS v3.4.3 allows attackers to execut... |
| CVE-2024-7209 | MEDIUM | 6.5 | 0.3% | Jul 30, 2024 | A vulnerability exists in the use of shared SPF records in multi-tenant hosting providers, allowing attackers to use net... |
| CVE-2024-7208 | MEDIUM | 6.5 | 0.4% | Jul 30, 2024 | A vulnerability in multi-tenant hosting allows an authenticated sender to spoof the identity of a shared, hosted domain,... |
| CVE-2024-5486 | MEDIUM | 4.9 | 0.3% | Jul 30, 2024 | A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access ... |
| CVE-2024-41944 | MEDIUM | 6.5 | 0.4% | Jul 30, 2024 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `report/data/proofofplay... |
| CVE-2024-41916 | MEDIUM | 4.9 | 0.4% | Jul 30, 2024 | A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access ... |
| CVE-2024-41804 | MEDIUM | 6.5 | 0.4% | Jul 30, 2024 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API route inside the CMS... |
| CVE-2024-41803 | MEDIUM | 4.9 | 0.4% | Jul 30, 2024 | Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CM... |
| CVE-2024-41109 | MEDIUM | 6.5 | 0.5% | Jul 30, 2024 | Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` wi... |
| CVE-2024-39320 | MEDIUM | 6.1 | 0.4% | Jul 30, 2024 | Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to... |
| CVE-2024-37165 | MEDIUM | 6.1 | 0.4% | Jul 30, 2024 | Discourse is an open source discussion platform. Prior to 3.2.3 and 3.3.0.beta3, improperly sanitized Onebox data could ... |
| CVE-2024-7127 | MEDIUM | 6.1 | 0.4% | Jul 30, 2024 | Improper Neutralization of Input During Web Page Generation vulnerability in Stackposts Social Marketing Tool allows Cro... |
| CVE-2024-41701 | MEDIUM | 5.3 | 0.3% | Jul 30, 2024 | AccuPOS - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2024-7225 | MEDIUM | 5.4 | 0.5% | Jul 30, 2024 | A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been classified as problematic. This... |
| CVE-2024-41694 | MEDIUM | 5.3 | 0.3% | Jul 30, 2024 | Cybonet - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2024-41693 | MEDIUM | 6.1 | 0.3% | Jul 30, 2024 | Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) |
| CVE-2024-41141 | MEDIUM | 6.1 | 0.3% | Jul 30, 2024 | Stored cross-site scripting vulnerability exists in EC-CUBE Web API Plugin. When there are multiple users using OAuth Ma... |
| CVE-2024-40895 | MEDIUM | 6.4 | 0.4% | Jul 30, 2024 | FFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a re... |
| CVE-2024-38430 | MEDIUM | 6.1 | 0.2% | Jul 30, 2024 | Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2024-42231 | MEDIUM | 5.5 | 0.2% | Jul 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix calc_available_free_space() for z... |
| CVE-2024-42230 | MEDIUM | 4.4 | 0.2% | Jul 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries: Fix scv instruction crash with kex... |
| CVE-2024-42229 | MEDIUM | 4.1 | 0.2% | Jul 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: crypto: aead,cipher - zeroize key buffer after use ... |
| CVE-2024-42227 | MEDIUM | 4.7 | 0.2% | Jul 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix overlapping copy within dml_co... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now