2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39310 | MEDIUM | 5.4 | 0.3% | Jul 1, 2024 | The Basil recipe theme for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `post_title` paramet... |
| CVE-2024-37764 | MEDIUM | 5.4 | 0.6% | Jul 1, 2024 | MachForm up to version 19 is affected by an authenticated stored cross-site scripting. |
| CVE-2024-37763 | MEDIUM | 5.4 | 0.7% | Jul 1, 2024 | MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid s... |
| CVE-2024-23737 | MEDIUM | 5.4 | 0.1% | Jul 1, 2024 | Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows a... |
| CVE-2024-32228 | MEDIUM | 6.6 | 0.2% | Jul 1, 2024 | FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end. |
| CVE-2024-39303 | MEDIUM | 5.4 | 0.3% | Jul 1, 2024 | Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when resto... |
| CVE-2024-37146 | MEDIUM | 6.1 | 0.4% | Jul 1, 2024 | Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a ... |
| CVE-2024-37145 | MEDIUM | 6.1 | 0.5% | Jul 1, 2024 | Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a ... |
| CVE-2024-36423 | MEDIUM | 6.1 | 0.4% | Jul 1, 2024 | Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a ... |
| CVE-2024-36387 | MEDIUM | 5.4 | 1.7% | Jul 1, 2024 | Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a cr... |
| CVE-2024-39879 | MEDIUM | 5.3 | 0.3% | Jul 1, 2024 | In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings |
| CVE-2024-39878 | MEDIUM | 5.3 | 0.3% | Jul 1, 2024 | In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection |
| CVE-2024-36996 | MEDIUM | 5.3 | 0.4% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an a... |
| CVE-2024-36994 | MEDIUM | 5.4 | 0.3% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9... |
| CVE-2024-36993 | MEDIUM | 5.4 | 0.4% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9... |
| CVE-2024-36992 | MEDIUM | 5.4 | 0.3% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9... |
| CVE-2024-36990 | MEDIUM | 6.5 | 0.7% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an a... |
| CVE-2024-36989 | MEDIUM | 4.3 | 0.3% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a lo... |
| CVE-2024-36987 | MEDIUM | 6.5 | 0.3% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an a... |
| CVE-2024-36986 | MEDIUM | 5.7 | 0.4% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9... |
| CVE-2024-20399 | MEDIUM | 6.7 | 4.3% | Jul 1, 2024 | A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator cred... |
| CVE-2024-36422 | MEDIUM | 6.1 | 0.4% | Jul 1, 2024 | Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a ... |
| CVE-2024-6375 | MEDIUM | 6.5 | 0.4% | Jul 1, 2024 | A command for refining a collection shard key is missing an authorization check. This may cause the command to run direc... |
| CVE-2024-34696 | MEDIUM | 4.9 | 0.4% | Jul 1, 2024 | GeoServer is an open source server that allows users to share and edit geospatial data. Starting in version 2.10.0 and p... |
| CVE-2024-21462 | MEDIUM | 5.5 | 0.1% | Jul 1, 2024 | Transient DOS while loading the TA ELF file. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now