2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24764 | MEDIUM | 4.8 | 0.3% | Jun 26, 2024 | October is a self-hosted CMS platform based on the Laravel PHP Framework. This issue affects authenticated administrator... |
| CVE-2024-4869 | MEDIUM | 6.1 | 0.4% | Jun 26, 2024 | The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2024-29954 | MEDIUM | 5.5 | 0.1% | Jun 26, 2024 | A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e ... |
| CVE-2024-29953 | MEDIUM | 4.3 | 0.3% | Jun 26, 2024 | A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session pas... |
| CVE-2024-30931 | MEDIUM | 6.1 | 0.3% | Jun 25, 2024 | Stored Cross Site Scripting vulnerability in Emby Media Server Emby Media Server 4.8.3.0 allows a remote attacker to esc... |
| CVE-2024-30112 | MEDIUM | 5.4 | 0.3% | Jun 25, 2024 | HCL Connections is vulnerable to a cross-site scripting attack where an attacker may leverage this issue to execute arbi... |
| CVE-2024-5017 | MEDIUM | 6.5 | 1.6% | Jun 25, 2024 | In WhatsUp Gold versions released before 2023.1.3, a path traversal vulnerability exists. A specially crafted unauthenti... |
| CVE-2024-5014 | MEDIUM | 6.5 | 0.5% | Jun 25, 2024 | In WhatsUp Gold versions released before 2023.1.3, a Server Side Request Forgery vulnerability exists in the GetASPRepor... |
| CVE-2024-35526 | MEDIUM | 5.9 | 0.2% | Jun 25, 2024 | An issue in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to access sensitive information in t... |
| CVE-2024-34400 | MEDIUM | 6.1 | 0.3% | Jun 25, 2024 | An issue was discovered in VirtoSoftware Virto Kanban Board Web Part before 5.3.5.1 for SharePoint 2019. There is /_layo... |
| CVE-2024-21739 | MEDIUM | 5.3 | 0.3% | Jun 25, 2024 | Geehy APM32F103CCT6, APM32F103RCT6, APM32F103RCT7, and APM32F103VCT6 devices have Incorrect Access Control. |
| CVE-2024-37894 | MEDIUM | 6.3 | 6.3% | Jun 25, 2024 | Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when ass... |
| CVE-2024-37167 | MEDIUM | 4.3 | 0.4% | Jun 25, 2024 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see b... |
| CVE-2024-37820 | MEDIUM | 5.4 | 0.4% | Jun 25, 2024 | A nil pointer dereference in PingCAP TiDB v8.2.0-alpha-216-gfe5858b allows attackers to crash the application via expres... |
| CVE-2024-36819 | MEDIUM | 5.4 | 0.3% | Jun 25, 2024 | MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to inse... |
| CVE-2024-6238 | MEDIUM | 5.3 | 0.2% | Jun 25, 2024 | pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised ac... |
| CVE-2024-0171 | MEDIUM | 5.3 | 0.1% | Jun 25, 2024 | Dell PowerEdge Server BIOS contains an TOCTOU race condition vulnerability. A local low privileged attacker could potent... |
| CVE-2024-39470 | MEDIUM | 5.5 | 0.2% | Jun 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: eventfs: Fix a possible null pointer dereference in... |
| CVE-2024-39468 | MEDIUM | 5.5 | 0.2% | Jun 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix deadlock in smb2_find_smb_tcon() ... |
| CVE-2024-39466 | MEDIUM | 5.5 | 0.2% | Jun 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/qcom/lmh: Check for SCM availabilit... |
| CVE-2024-39465 | MEDIUM | 5.5 | 0.2% | Jun 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: media: mgb4: Fix double debugfs remove Fixes an er... |
| CVE-2024-39464 | MEDIUM | 5.5 | 0.2% | Jun 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Fix notifier list entry init st... |
| CVE-2024-39461 | MEDIUM | 5.5 | 0.2% | Jun 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: clk: bcm: rpi: Assign ->num before accessing ->hws ... |
| CVE-2024-39371 | MEDIUM | 5.5 | 0.2% | Jun 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: io_uring: check for non-NULL file pointer in io_fil... |
| CVE-2024-39301 | MEDIUM | 5.5 | 0.2% | Jun 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: net/9p: fix uninit-value in p9_client_rpc() Syzbot... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now