2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36457 | MEDIUM | 5.3 | 0.3% | Jul 15, 2024 | The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint. |
| CVE-2024-6741 | MEDIUM | 5.3 | 0.6% | Jul 15, 2024 | Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers c... |
| CVE-2024-6398 | MEDIUM | 5.3 | 0.3% | Jul 15, 2024 | An information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows inform... |
| CVE-2024-39767 | MEDIUM | 6.5 | 0.2% | Jul 15, 2024 | Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually cam... |
| CVE-2024-32945 | MEDIUM | 5.3 | 0.2% | Jul 15, 2024 | Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows a... |
| CVE-2024-6740 | MEDIUM | 6.1 | 0.5% | Jul 15, 2024 | Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject Jav... |
| CVE-2024-6540 | MEDIUM | 5.3 | 0.4% | Jul 15, 2024 | Improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS cou... |
| CVE-2024-6742 | MEDIUM | 5.4 | 0.3% | Jul 15, 2024 | AguardNet Technology's Space Management System does not properly filter user input, allowing remote attackers with regul... |
| CVE-2024-6289 | MEDIUM | 6.1 | 0.9% | Jul 15, 2024 | The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect W... |
| CVE-2024-6076 | MEDIUM | 6.1 | 0.4% | Jul 15, 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputtin... |
| CVE-2024-6074 | MEDIUM | 6.1 | 0.3% | Jul 15, 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputtin... |
| CVE-2024-6073 | MEDIUM | 6.1 | 0.3% | Jul 15, 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputtin... |
| CVE-2024-6072 | MEDIUM | 6.1 | 0.3% | Jul 15, 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter bef... |
| CVE-2024-6739 | MEDIUM | 6.1 | 0.4% | Jul 15, 2024 | The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote att... |
| CVE-2024-6738 | MEDIUM | 5.3 | 0.5% | Jul 15, 2024 | The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers t... |
| CVE-2024-39741 | MEDIUM | 5.3 | 0.7% | Jul 15, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to traverse directories on the... |
| CVE-2024-39740 | MEDIUM | 5.3 | 0.4% | Jul 15, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 displays version information in HTTP requests that could all... |
| CVE-2024-39735 | MEDIUM | 5.4 | 0.3% | Jul 15, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability al... |
| CVE-2024-39729 | MEDIUM | 4.3 | 0.4% | Jul 15, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow an authenticated user to obtain sensitive inform... |
| CVE-2024-39739 | MEDIUM | 4.3 | 0.2% | Jul 15, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to server-side request forgery (SSRF). This ma... |
| CVE-2024-39737 | MEDIUM | 5.3 | 0.4% | Jul 15, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to obtain sensitive informatio... |
| CVE-2024-39728 | MEDIUM | 5.4 | 0.3% | Jul 15, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to stored cross-site scripting. This vulnerabi... |
| CVE-2024-39734 | MEDIUM | 4.3 | 0.2% | Jul 14, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or... |
| CVE-2024-39733 | MEDIUM | 5.5 | 0.1% | Jul 14, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 stores user credentials in plain clear text which can be rea... |
| CVE-2024-6730 | MEDIUM | 6.3 | 0.4% | Jul 14, 2024 | A vulnerability was found in Nanjing Xingyuantu Technology SparkShop up to 1.1.6. It has been rated as critical. This is... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now