2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39488 | MEDIUM | 5.5 | 0.2% | Jul 10, 2024 | In the Linux kernel, the following vulnerability has been resolved: arm64: asm-bug: Add .align 2 to the end of __BUG_EN... |
| CVE-2024-36453 | MEDIUM | 6.1 | 0.4% | Jul 10, 2024 | Cross-site scripting vulnerability exists in session_login.cgi of Webmin versions prior to 1.970 and Usermin versions pr... |
| CVE-2024-36450 | MEDIUM | 5.4 | 0.3% | Jul 10, 2024 | Cross-site scripting vulnerability exists in sysinfo.cgi of Webmin versions prior to 1.910. If this vulnerability is exp... |
| CVE-2024-6410 | MEDIUM | 4.3 | 0.4% | Jul 10, 2024 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Ref... |
| CVE-2024-39330 | MEDIUM | 4.3 | 1.0% | Jul 10, 2024 | An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the django.core.files.stora... |
| CVE-2024-39329 | MEDIUM | 5.3 | 0.9% | Jul 10, 2024 | An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend.... |
| CVE-2024-6550 | MEDIUM | 5.3 | 0.5% | Jul 10, 2024 | The Gravity Forms: Multiple Form Instances plugin for WordPress is vulnerable to Full Path Disclosure in all versions up... |
| CVE-2024-5677 | MEDIUM | 4.3 | 0.3% | Jul 10, 2024 | The Featured Image Generator plugin for WordPress is vulnerable to unauthorized image upload due to a missing capability... |
| CVE-2024-4866 | MEDIUM | 5.4 | 0.4% | Jul 10, 2024 | The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere El... |
| CVE-2024-25023 | MEDIUM | 5.5 | 0.1% | Jul 10, 2024 | IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores p... |
| CVE-2024-22477 | MEDIUM | 4.3 | 0.2% | Jul 9, 2024 | A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained ... |
| CVE-2024-22377 | MEDIUM | 5.3 | 0.4% | Jul 9, 2024 | The deploy directory in PingFederate runtime nodes is reachable to unauthorized users. |
| CVE-2024-39901 | MEDIUM | 5.4 | 0.3% | Jul 9, 2024 | OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the Op... |
| CVE-2024-39900 | MEDIUM | 5.4 | 0.3% | Jul 9, 2024 | OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the... |
| CVE-2024-38963 | MEDIUM | 6.1 | 0.3% | Jul 9, 2024 | Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined "AddProductReview.Title" and "AddProduct... |
| CVE-2024-21993 | MEDIUM | 6.5 | 0.2% | Jul 9, 2024 | SnapCenter versions prior to 5.0p1 are susceptible to a vulnerability which could allow an authenticated attacker to di... |
| CVE-2024-39181 | MEDIUM | 6.5 | 0.5% | Jul 9, 2024 | Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a buffer overflow via the ApCliSsid pa... |
| CVE-2024-39072 | MEDIUM | 5.5 | 0.4% | Jul 9, 2024 | AMTT Hotel Broadband Operation System (HiBOS) v3.0.3.151204 is vulnerable to SQL injection via manager/conference/calend... |
| CVE-2024-39031 | MEDIUM | 5.4 | 0.8% | Jul 9, 2024 | In Silverpeas Core <= 6.3.5, in Mes Agendas, a user can create new events and add them to their calendar. Additionally, ... |
| CVE-2024-38959 | MEDIUM | 6.1 | 0.7% | Jul 9, 2024 | Cross Site Scripting vulnerability in Creativeitem Academy LMS Learning Management System v.6.8.1 allows a remote attack... |
| CVE-2024-37865 | MEDIUM | 5.9 | 0.7% | Jul 9, 2024 | An issue in S3Browser v.11.4.5 and v.10.9.9 and fixed in v.11.5.7 allows a remote attacker to obtain sensitive informati... |
| CVE-2024-34721 | MEDIUM | 5.5 | 0.1% | Jul 9, 2024 | In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to imprope... |
| CVE-2024-31314 | MEDIUM | 5.5 | 0.1% | Jul 9, 2024 | In multiple functions of ShortcutService.java, there is a possible persistent DOS due to resource exhaustion. This could... |
| CVE-2024-31312 | MEDIUM | 5.5 | 0.1% | Jul 9, 2024 | In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local ... |
| CVE-2024-27386 | MEDIUM | 6.7 | 0.2% | Jul 9, 2024 | A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now