2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38013 | MEDIUM | 6.7 | 0.6% | Jul 9, 2024 | Microsoft Windows Server Backup Elevation of Privilege Vulnerability |
| CVE-2024-35270 | MEDIUM | 5.3 | 0.9% | Jul 9, 2024 | Windows iSCSI Service Denial of Service Vulnerability |
| CVE-2024-30071 | MEDIUM | 4.7 | 0.6% | Jul 9, 2024 | Windows Remote Access Connection Manager Information Disclosure Vulnerability |
| CVE-2024-26279 | MEDIUM | 6.1 | 0.5% | Jul 9, 2024 | The wrapper extensions do not correctly validate inputs, leading to XSS vectors. |
| CVE-2024-26278 | MEDIUM | 6.1 | 0.4% | Jul 9, 2024 | The Custom Fields component not correctly filter inputs, leading to a XSS vector. |
| CVE-2024-26184 | MEDIUM | 6.8 | 1.0% | Jul 9, 2024 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2024-21731 | MEDIUM | 6.1 | 0.4% | Jul 9, 2024 | Improper handling of input could lead to an XSS vector in the StringHelper::truncate method. |
| CVE-2024-21730 | MEDIUM | 5.4 | 0.4% | Jul 9, 2024 | The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector. |
| CVE-2024-21729 | MEDIUM | 6.1 | 0.4% | Jul 9, 2024 | Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field. |
| CVE-2024-33509 | MEDIUM | 4.8 | 0.2% | Jul 9, 2024 | An improper certificate validation vulnerability [CWE-295] in FortiWeb 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all ve... |
| CVE-2024-27785 | MEDIUM | 6.5 | 0.4% | Jul 9, 2024 | An improper neutralization of formula elements in a CSV File [CWE-1236] vulnerability in Fortinet FortiAIOps 2.0.0 may a... |
| CVE-2024-27784 | MEDIUM | 6.5 | 0.8% | Jul 9, 2024 | Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet Forti... |
| CVE-2024-26015 | MEDIUM | 4.7 | 0.5% | Jul 9, 2024 | An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, v... |
| CVE-2024-21759 | MEDIUM | 4.3 | 0.3% | Jul 9, 2024 | An authorization bypass through user-controlled key in Fortinet FortiPortal version 7.2.0, and versions 7.0.0 through 7.... |
| CVE-2024-6614 | MEDIUM | 4.3 | 0.4% | Jul 9, 2024 | The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. Th... |
| CVE-2024-6613 | MEDIUM | 5.5 | 0.2% | Jul 9, 2024 | The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. Th... |
| CVE-2024-6612 | MEDIUM | 5.3 | 0.5% | Jul 9, 2024 | CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This cause... |
| CVE-2024-6610 | MEDIUM | 4.3 | 0.3% | Jul 9, 2024 | Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to p... |
| CVE-2024-6608 | MEDIUM | 4.3 | 0.4% | Jul 9, 2024 | It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewp... |
| CVE-2024-6601 | MEDIUM | 4.7 | 0.4% | Jul 9, 2024 | A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerabilit... |
| CVE-2024-6600 | MEDIUM | 6.3 | 0.4% | Jul 9, 2024 | Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allo... |
| CVE-2024-6598 | MEDIUM | 6.5 | 0.5% | Jul 9, 2024 | A denial-of-service attack is possible through the execution functionality of KNIME Business Hub 1.10.0 and 1.10.1. It a... |
| CVE-2024-2177 | MEDIUM | 6.8 | 0.7% | Jul 9, 2024 | A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 ... |
| CVE-2024-6391 | MEDIUM | 6.4 | 0.3% | Jul 9, 2024 | The oik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bw_button shortcode in all ve... |
| CVE-2024-39876 | MEDIUM | 4 | 0.2% | Jul 9, 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now