2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37034 | MEDIUM | 5.9 | 0.2% | Jul 26, 2024 | An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are... |
| CVE-2024-42007 | MEDIUM | 5.8 | 0.6% | Jul 26, 2024 | SPX (aka php-spx) through 0.4.15 allows SPX_UI_URI Directory Traversal to read arbitrary files. |
| CVE-2024-41375 | MEDIUM | 6.1 | 0.3% | Jul 26, 2024 | ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php |
| CVE-2024-41374 | MEDIUM | 6.1 | 0.3% | Jul 26, 2024 | ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php |
| CVE-2024-41373 | MEDIUM | 6.3 | 0.4% | Jul 26, 2024 | ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php. |
| CVE-2024-27357 | MEDIUM | 5.8 | 0.2% | Jul 26, 2024 | An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through... |
| CVE-2024-41356 | MEDIUM | 4.7 | 0.4% | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\firewall-zones\zones-edit-network.php. |
| CVE-2024-41355 | MEDIUM | 6.5 | 0.4% | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php. |
| CVE-2024-41805 | MEDIUM | 6.1 | 0.4% | Jul 26, 2024 | Tracks, a Getting Things Done (GTD) web application, is vulnerable to reflected cross-site scripting in versions prior t... |
| CVE-2024-7128 | MEDIUM | 5.3 | 0.4% | Jul 26, 2024 | A flaw was found in the OpenShift console. Several endpoints in the application use the authHandler() and authHandlerWit... |
| CVE-2024-6922 | MEDIUM | 6.9 | 30.2% | Jul 26, 2024 | Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component. An attac... |
| CVE-2024-41691 | MEDIUM | 4.6 | 0.2% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within th... |
| CVE-2024-41690 | MEDIUM | 4.6 | 0.2% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credenti... |
| CVE-2024-41689 | MEDIUM | 4.6 | 0.2% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials withi... |
| CVE-2024-41688 | MEDIUM | 4.6 | 0.1% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passw... |
| CVE-2024-41684 | MEDIUM | 5.3 | 0.2% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for the session cookies assoc... |
| CVE-2024-25090 | MEDIUM | 5.4 | 0.7% | Jul 26, 2024 | Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name... |
| CVE-2024-6490 | MEDIUM | 6.5 | 0.2% | Jul 26, 2024 | During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was found, which allows an un... |
| CVE-2024-40897 | MEDIUM | 6.7 | 0.4% | Jul 26, 2024 | Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricke... |
| CVE-2024-3938 | MEDIUM | 6.1 | 0.2% | Jul 25, 2024 | The "reset password" login page accepted an HTML injection via URL parameters. This has already been rectified via patc... |
| CVE-2024-38103 | MEDIUM | 5.9 | 0.4% | Jul 25, 2024 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2024-41809 | MEDIUM | 6.1 | 0.4% | Jul 25, 2024 | OpenObserve is an open-source observability platform. Starting in version 0.4.4 and prior to version 0.10.0, OpenObserve... |
| CVE-2024-6558 | MEDIUM | 6.1 | 0.2% | Jul 25, 2024 | HMS Industrial Networks Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanita... |
| CVE-2024-41808 | MEDIUM | 5.4 | 0.6% | Jul 25, 2024 | The OpenObserve open-source observability platform provides the ability to filter logs in a dashboard by the values uplo... |
| CVE-2024-40324 | MEDIUM | 5.4 | 0.6% | Jul 25, 2024 | A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) charac... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now