2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38207 | MEDIUM | 6.3 | 0.4% | Aug 23, 2024 | Microsoft Edge (HTML-based) Memory Corruption Vulnerability |
| CVE-2024-40111 | MEDIUM | 4.8 | 0.8% | Aug 23, 2024 | A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulner... |
| CVE-2024-37392 | MEDIUM | 6.1 | 0.2% | Aug 23, 2024 | A stored Cross-Site Scripting (XSS) vulnerability has been identified in SMSEagle software version < 6.0. The vulnerabil... |
| CVE-2024-45190 | MEDIUM | 6.5 | 0.9% | Aug 23, 2024 | Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal ... |
| CVE-2024-45189 | MEDIUM | 6.5 | 0.9% | Aug 23, 2024 | Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal ... |
| CVE-2024-45188 | MEDIUM | 6.5 | 0.9% | Aug 23, 2024 | Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal ... |
| CVE-2024-45187 | HIGH | 8.8 | 0.5% | Aug 23, 2024 | Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high p... |
| CVE-2024-42914 | CRITICAL | 9.1 | 0.6% | Aug 23, 2024 | A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending ... |
| CVE-2024-42845 | HIGH | 8 | 2.7% | Aug 23, 2024 | An eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 al... |
| CVE-2024-7954 | CRITICAL | 9.8 | 89.8% | Aug 23, 2024 | The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution ... |
| CVE-2024-42992 | — | — | — | Aug 23, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-42852 | MEDIUM | 6.1 | 0.7% | Aug 23, 2024 | Cross Site Scripting vulnerability in AcuToWeb server v.10.5.0.7577C8b allows a remote attacker to execute arbitrary cod... |
| CVE-2024-7428 | MEDIUM | 4.8 | 0.4% | Aug 23, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in OpenText™ Network Node Manager i (NNMi) allows URL ... |
| CVE-2024-7427 | MEDIUM | 4.8 | 0.4% | Aug 23, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ N... |
| CVE-2024-44390 | HIGH | 8.8 | 0.3% | Aug 23, 2024 | Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset. |
| CVE-2024-44387 | MEDIUM | 6.5 | 0.3% | Aug 23, 2024 | Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the functino formWrlExtraGet. |
| CVE-2024-43794 | MEDIUM | 6.1 | 0.2% | Aug 23, 2024 | OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSea... |
| CVE-2024-42918 | MEDIUM | 5.4 | 0.4% | Aug 23, 2024 | itsourcecode Online Accreditation Management System contains a Cross Site Scripting vulnerability, which allows an attac... |
| CVE-2024-42531 | CRITICAL | 9.8 | 0.6% | Aug 23, 2024 | Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a... |
| CVE-2024-41878 | MEDIUM | 5.4 | 0.3% | Aug 23, 2024 | Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2024-41877 | MEDIUM | 5.4 | 0.3% | Aug 23, 2024 | Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-41876 | MEDIUM | 5.4 | 0.3% | Aug 23, 2024 | Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2024-41875 | MEDIUM | 5.4 | 0.3% | Aug 23, 2024 | Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-41849 | MEDIUM | 4.1 | 0.4% | Aug 23, 2024 | Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that cou... |
| CVE-2024-41848 | MEDIUM | 5.4 | 0.3% | Aug 23, 2024 | Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now