2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2926 | MEDIUM | 5.4 | 0.4% | Jul 4, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widg... |
| CVE-2024-38471 | MEDIUM | 6.8 | 0.4% | Jul 4, 2024 | Multiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS com... |
| CVE-2024-38344 | MEDIUM | 5.4 | 0.3% | Jul 4, 2024 | A cross-site request forgery vulnerability exists in WP Tweet Walls versions prior to 1.0.4. If this vulnerability is ex... |
| CVE-2024-6383 | MEDIUM | 5.3 | 0.6% | Jul 3, 2024 | The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might atte... |
| CVE-2024-39683 | MEDIUM | 6.5 | 0.6% | Jul 3, 2024 | ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of ... |
| CVE-2024-37157 | MEDIUM | 5.3 | 0.3% | Jul 3, 2024 | Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 o... |
| CVE-2024-36122 | MEDIUM | 4.3 | 0.4% | Jul 3, 2024 | Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 o... |
| CVE-2024-36113 | MEDIUM | 6.5 | 0.4% | Jul 3, 2024 | Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch, version 3.3.0.beta3 on t... |
| CVE-2024-35234 | MEDIUM | 6.1 | 0.3% | Jul 3, 2024 | Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 o... |
| CVE-2024-33870 | MEDIUM | 6.3 | 0.5% | Jul 3, 2024 | An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript documen... |
| CVE-2024-33869 | MEDIUM | 5.3 | 0.4% | Jul 3, 2024 | An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a cra... |
| CVE-2024-29510 | MEDIUM | 6.3 | 28.0% | Jul 3, 2024 | Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with ... |
| CVE-2024-29507 | MEDIUM | 5.4 | 0.7% | Jul 3, 2024 | Artifex Ghostscript before 10.03.0 sometimes has a stack-based buffer overflow via the CIDFSubstPath and CIDFSubstFont p... |
| CVE-2024-5821 | MEDIUM | 6.2 | 0.2% | Jul 3, 2024 | The vulnerability allows an attacker to access sensitive files on the server by confusing the agent with incorrect file ... |
| CVE-2024-31223 | MEDIUM | 5.3 | 1.1% | Jul 3, 2024 | Fides is an open-source privacy engineering platform, and `SERVER_SIDE_FIDES_API_URL` is a server-side configuration env... |
| CVE-2024-3332 | MEDIUM | 6.5 | 0.4% | Jul 3, 2024 | A malicious BLE device can send a specific order of packet sequence to cause a DoS attack on the victim BLE device |
| CVE-2024-39248 | MEDIUM | 5.4 | 0.7% | Jul 3, 2024 | A cross-site scripting (XSS) vulnerability in SimpCMS v0.1 allows attackers to execute arbitrary web scripts or HTML via... |
| CVE-2024-6052 | MEDIUM | 5.4 | 0.4% | Jul 3, 2024 | Stored XSS in Checkmk before versions 2.3.0p8, 2.2.0p29, 2.1.0p45, and 2.0.0 (EOL) allows users to execute arbitrary scr... |
| CVE-2024-39220 | MEDIUM | 6.5 | 0.4% | Jul 3, 2024 | BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD, AV-02FDE, A... |
| CVE-2024-37726 | MEDIUM | 6.8 | 0.9% | Jul 3, 2024 | Insecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to... |
| CVE-2024-6428 | MEDIUM | 6.5 | 0.4% | Jul 3, 2024 | Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when cre... |
| CVE-2024-39830 | MEDIUM | 5.9 | 0.4% | Jul 3, 2024 | Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled,... |
| CVE-2024-39807 | MEDIUM | 5.3 | 0.3% | Jul 3, 2024 | Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an... |
| CVE-2024-39361 | MEDIUM | 5.4 | 0.3% | Jul 3, 2024 | Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a Rem... |
| CVE-2024-36257 | MEDIUM | 5.3 | 0.3% | Jul 3, 2024 | Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now