2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39308 | MEDIUM | 5.4 | 0.6% | Jul 8, 2024 | RailsAdmin is a Rails engine that provides an interface for managing data. RailsAdmin list view has the XSS vulnerabilit... |
| CVE-2024-4341 | MEDIUM | 6.5 | 0.3% | Jul 8, 2024 | Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in ExtremePacs Extreme XDS allows ... |
| CVE-2024-6163 | MEDIUM | 5.3 | 0.5% | Jul 8, 2024 | Certain http endpoints of Checkmk in Checkmk < 2.3.0p10 < 2.2.0p31, < 2.1.0p46, <= 2.0.0p39 allows remote attacker to by... |
| CVE-2024-37389 | MEDIUM | 5.4 | 24.0% | Jul 8, 2024 | Apache NiFi 1.10.0 through 1.26.0 and 2.0.0-M1 through 2.0.0-M3 support a description field in the Parameter Context con... |
| CVE-2024-34603 | MEDIUM | 5.5 | 0.1% | Jul 8, 2024 | Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location dat... |
| CVE-2024-34602 | MEDIUM | 5.5 | 0.2% | Jul 8, 2024 | Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local atta... |
| CVE-2024-37528 | MEDIUM | 5.4 | 0.3% | Jul 8, 2024 | IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21... |
| CVE-2024-31897 | MEDIUM | 4.3 | 0.3% | Jul 8, 2024 | IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21... |
| CVE-2024-39723 | MEDIUM | 4.6 | 0.2% | Jul 8, 2024 | IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator. A user with physic... |
| CVE-2024-5711 | MEDIUM | 6.1 | 0.5% | Jul 8, 2024 | A stored Cross-Site Scripting (XSS) vulnerability exists in the stitionai/devika chat feature, allowing attackers to inj... |
| CVE-2024-6539 | MEDIUM | 4.8 | 0.3% | Jul 7, 2024 | A vulnerability classified as problematic has been found in heyewei SpringBootCMS up to 2024-05-28. Affected is an unkno... |
| CVE-2024-6229 | MEDIUM | 5.4 | 0.3% | Jul 7, 2024 | A stored cross-site scripting (XSS) vulnerability exists in the 'Upload Knowledge' feature of stangirard/quivr, affectin... |
| CVE-2024-40605 | MEDIUM | 4.8 | 0.3% | Jul 7, 2024 | An issue was discovered in the Foreground skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar t... |
| CVE-2024-40604 | MEDIUM | 4.8 | 0.3% | Jul 7, 2024 | An issue was discovered in the Nimbus skin for MediaWiki through 1.42.1. There is Stored XSS via MediaWiki:Nimbus-sideba... |
| CVE-2024-40603 | MEDIUM | 4.3 | 0.2% | Jul 7, 2024 | An issue was discovered in the ArticleRatings extension for MediaWiki through 1.42.1. Special:ChangeRating allows CSRF t... |
| CVE-2024-40602 | MEDIUM | 4.8 | 0.3% | Jul 7, 2024 | An issue was discovered in the Tempo skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-le... |
| CVE-2024-40601 | MEDIUM | 6.5 | 0.2% | Jul 7, 2024 | An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules. |
| CVE-2024-40600 | MEDIUM | 4.8 | 0.3% | Jul 7, 2024 | An issue was discovered in the Metrolook skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar to... |
| CVE-2024-40599 | MEDIUM | 4.8 | 0.3% | Jul 7, 2024 | An issue was discovered in the GuMaxDD skin for MediaWiki through 1.42.1. There is stored XSS via MediaWiki:Sidebar top-... |
| CVE-2024-40598 | MEDIUM | 4.3 | 0.3% | Jul 7, 2024 | An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed informati... |
| CVE-2024-40596 | MEDIUM | 4.3 | 0.3% | Jul 7, 2024 | An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special:Investigate feature can exp... |
| CVE-2024-6095 | MEDIUM | 5.8 | 2.5% | Jul 6, 2024 | A vulnerability in the /models/apply endpoint of mudler/localai versions 2.15.0 allows for Server-Side Request Forgery (... |
| CVE-2024-37554 | MEDIUM | 5.4 | 0.2% | Jul 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam Ultra... |
| CVE-2024-37553 | MEDIUM | 5.4 | 0.3% | Jul 6, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Axelerant T... |
| CVE-2024-37547 | MEDIUM | 6.5 | 0.5% | Jul 6, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Livemesh Livemesh Addons... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now