2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39776 | HIGH | 7.5 | 0.4% | Aug 22, 2024 | Avtec Outpost stores sensitive information in an insecure location without proper access controls in place. |
| CVE-2024-8088 | HIGH | 8.7 | 1.3% | Aug 22, 2024 | There is a HIGH severity vulnerability affecting the CPython "zipfile" module affecting "zipfile.Path". Note that the mo... |
| CVE-2024-39717 | HIGH | 7.2 | 4.0% | Aug 22, 2024 | The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only avai... |
| CVE-2024-7634 | MEDIUM | 4.9 | 0.5% | Aug 22, 2024 | NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwri... |
| CVE-2024-42773 | CRITICAL | 9.1 | 0.5% | Aug 22, 2024 | An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management Sys... |
| CVE-2024-42767 | HIGH | 7.2 | 0.6% | Aug 22, 2024 | Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php. |
| CVE-2024-42776 | HIGH | 7.2 | 0.5% | Aug 22, 2024 | Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php. |
| CVE-2024-42775 | CRITICAL | 9.1 | 0.5% | Aug 22, 2024 | An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management Syst... |
| CVE-2024-42774 | HIGH | 7.5 | 0.4% | Aug 22, 2024 | An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0,... |
| CVE-2024-42772 | HIGH | 7.5 | 0.5% | Aug 22, 2024 | An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which... |
| CVE-2024-42768 | MEDIUM | 6.8 | 0.2% | Aug 22, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_... |
| CVE-2024-8041 | MEDIUM | 6.5 | 0.5% | Aug 22, 2024 | A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 17.1.6, 17.2 prior t... |
| CVE-2024-7110 | MEDIUM | 6.4 | 0.3% | Aug 22, 2024 | An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prio... |
| CVE-2024-6502 | MEDIUM | 6.5 | 0.3% | Aug 22, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prio... |
| CVE-2024-45193 | MEDIUM | 4.3 | 0.3% | Aug 22, 2024 | An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validati... |
| CVE-2024-45192 | MEDIUM | 5.3 | 0.5% | Aug 22, 2024 | An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decodi... |
| CVE-2024-45191 | MEDIUM | 5.3 | 0.5% | Aug 22, 2024 | An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks du... |
| CVE-2024-43780 | MEDIUM | 4.3 | 0.3% | Aug 22, 2024 | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a gu... |
| CVE-2024-42771 | MEDIUM | 4.8 | 0.4% | Aug 22, 2024 | A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel... |
| CVE-2024-42770 | MEDIUM | 4.7 | 0.5% | Aug 22, 2024 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management Sys... |
| CVE-2024-42769 | MEDIUM | 6.1 | 0.4% | Aug 22, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management... |
| CVE-2024-42497 | MEDIUM | 4.9 | 0.3% | Aug 22, 2024 | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permission... |
| CVE-2024-42490 | HIGH | 7.5 | 0.6% | Aug 22, 2024 | authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentica... |
| CVE-2024-40884 | LOW | 2.7 | 0.4% | Aug 22, 2024 | Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user... |
| CVE-2024-3127 | MEDIUM | 4.3 | 0.3% | Aug 22, 2024 | An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now