2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6783 | MEDIUM | 4.8 | 0.5% | Jul 23, 2024 | A vulnerability has been discovered in Vue, that allows an attacker to perform XSS via prototype pollution. The attacker... |
| CVE-2024-41836 | MEDIUM | 5.5 | 0.2% | Jul 23, 2024 | InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a NULL Pointer Dereference vulnerability that cou... |
| CVE-2024-34128 | MEDIUM | 5.4 | 0.3% | Jul 23, 2024 | Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-41012 | MEDIUM | 6.3 | 0.2% | Jul 23, 2024 | In the Linux kernel, the following vulnerability has been resolved: filelock: Remove locks reliably when fcntl/close ra... |
| CVE-2024-6231 | MEDIUM | 5.9 | 0.3% | Jul 23, 2024 | The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2024-4260 | MEDIUM | 6.5 | 0.5% | Jul 23, 2024 | The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts vi... |
| CVE-2024-1575 | MEDIUM | 6.5 | 0.3% | Jul 23, 2024 | The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions ... |
| CVE-2024-24507 | MEDIUM | 6.1 | 0.4% | Jul 22, 2024 | Cross Site Scripting vulnerability in Act-On 2023 allows a remote attacker to execute arbitrary code via the newUser par... |
| CVE-2024-6638 | MEDIUM | 5.5 | 0.2% | Jul 22, 2024 | An integer overflow vulnerability due to improper input validation when reading TDMS files in LabVIEW may result in an i... |
| CVE-2024-6122 | MEDIUM | 5.5 | 0.2% | Jul 22, 2024 | An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may r... |
| CVE-2024-41880 | MEDIUM | 5.3 | 0.3% | Jul 22, 2024 | In veilid-core in Veilid before 0.3.4, the protocol's ping function can be misused in a way that decreases the effective... |
| CVE-2024-40075 | MEDIUM | 4.3 | 0.5% | Jul 22, 2024 | Laravel v11.x was discovered to contain an XML External Entity (XXE) vulnerability. |
| CVE-2024-37380 | MEDIUM | 5.3 | 0.2% | Jul 22, 2024 | A misconfiguration on UniFi U6+ Access Point could cause an incorrect VLAN traffic forwarding to APs meshed to UniFi U6+... |
| CVE-2024-41130 | MEDIUM | 6.5 | 0.3% | Jul 22, 2024 | llama.cpp provides LLM inference in C/C++. Prior to b3427, llama.cpp contains a null pointer dereference in gguf_init_fr... |
| CVE-2024-39688 | MEDIUM | 6.5 | 0.5% | Jul 22, 2024 | Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is concatenated wi... |
| CVE-2024-41828 | MEDIUM | 6.5 | 0.3% | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time |
| CVE-2024-41826 | MEDIUM | 4.8 | 0.3% | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page |
| CVE-2024-41825 | MEDIUM | 5.4 | 0.3% | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab |
| CVE-2024-41824 | MEDIUM | 6.5 | 0.3% | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific ca... |
| CVE-2024-41129 | MEDIUM | 4.4 | 0.2% | Jul 22, 2024 | The ops library is a Python framework for developing and testing Kubernetes and machine charms. The issue here is that o... |
| CVE-2024-32152 | MEDIUM | 4.3 | 11.3% | Jul 22, 2024 | A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted maliciou... |
| CVE-2024-29073 | MEDIUM | 6.5 | 10.8% | Jul 22, 2024 | An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe comm... |
| CVE-2024-41315 | MEDIUM | 6.8 | 2.1% | Jul 22, 2024 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet... |
| CVE-2024-41314 | MEDIUM | 6.8 | 2.1% | Jul 22, 2024 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the iface paramete... |
| CVE-2024-39902 | MEDIUM | 4.3 | 0.3% | Jul 22, 2024 | Tuleap is an open source suite to improve management of software developments and collaboration. Prior to Tuleap Communi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now