2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1937 | MEDIUM | 6.5 | 0.4% | Jul 16, 2024 | The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2024-41008 | MEDIUM | 5.5 | 0.2% | Jul 16, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: change vm->task_info handling This pat... |
| CVE-2024-6559 | MEDIUM | 5.3 | 0.4% | Jul 16, 2024 | The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin plugin for WordPress is vulnerable to Full Path ... |
| CVE-2024-4780 | MEDIUM | 6.4 | 0.5% | Jul 16, 2024 | The Image Hover Effects – Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eih... |
| CVE-2024-6557 | MEDIUM | 5.3 | 0.4% | Jul 16, 2024 | The SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Pos... |
| CVE-2024-4224 | MEDIUM | 5.4 | 0.3% | Jul 15, 2024 | An authenticated stored cross-site scripting (XSS) exists in the TP-Link TL-SG1016DE affecting version TL-SG1016DE(UN) V... |
| CVE-2024-40630 | MEDIUM | 4.3 | 0.4% | Jul 15, 2024 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
| CVE-2024-40627 | MEDIUM | 5.8 | 0.6% | Jul 15, 2024 | Fastapi OPA is an opensource fastapi middleware which includes auth flow. HTTP `OPTIONS` requests are always allowed by ... |
| CVE-2024-39918 | MEDIUM | 4.3 | 0.5% | Jul 15, 2024 | @jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots an... |
| CVE-2024-39912 | MEDIUM | 5.3 | 0.4% | Jul 15, 2024 | web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that ... |
| CVE-2024-38360 | MEDIUM | 4.9 | 0.5% | Jul 15, 2024 | Discourse is an open source platform for community discussion. In affected versions by creating replacement words with a... |
| CVE-2024-37386 | MEDIUM | 4.2 | 0.2% | Jul 15, 2024 | An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Cert... |
| CVE-2024-31946 | MEDIUM | 4.2 | 0.2% | Jul 15, 2024 | An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through ... |
| CVE-2024-39827 | MEDIUM | 5.5 | 0.2% | Jul 15, 2024 | Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an... |
| CVE-2024-39826 | MEDIUM | 6.8 | 0.4% | Jul 15, 2024 | Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct... |
| CVE-2024-39821 | MEDIUM | 4.4 | 0.1% | Jul 15, 2024 | Race condition in the installer for Zoom Workplace App for Windows and Zoom Rooms App for Windows may allow an authentic... |
| CVE-2024-39820 | MEDIUM | 5 | 0.2% | Jul 15, 2024 | Uncontrolled search path element in the installer for Zoom Workplace Desktop App for macOS before version 6.0.10 may all... |
| CVE-2024-37016 | MEDIUM | 6.8 | 0.3% | Jul 15, 2024 | Mengshen Wireless Door Alarm M70 2024-05-24 allows Authentication Bypass via a Capture-Replay approach. |
| CVE-2024-27238 | MEDIUM | 6.3 | 0.1% | Jul 15, 2024 | Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated ... |
| CVE-2024-40555 | MEDIUM | 5.3 | 0.3% | Jul 15, 2024 | Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability. |
| CVE-2024-40553 | MEDIUM | 4.9 | 0.3% | Jul 15, 2024 | Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage. |
| CVE-2024-38496 | MEDIUM | 5.1 | 0.3% | Jul 15, 2024 | The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group... |
| CVE-2024-38495 | MEDIUM | 5.3 | 0.3% | Jul 15, 2024 | A specific authentication strategy allows a malicious attacker to learn ids of all PAM users defined in its database. |
| CVE-2024-38493 | MEDIUM | 6.1 | 0.3% | Jul 15, 2024 | A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convi... |
| CVE-2024-36458 | MEDIUM | 5.1 | 0.2% | Jul 15, 2024 | The vulnerability allows a malicious low-privileged PAM user to perform server upgrade related actions. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now