2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36441 | MEDIUM | 5.4 | 0.3% | Aug 22, 2024 | Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to ope... |
| CVE-2024-43787 | MEDIUM | 5 | 0.2% | Aug 22, 2024 | Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypass... |
| CVE-2024-43785 | LOW | 2.5 | 0.2% | Aug 22, 2024 | gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. gitoxide-core, which provides most underlying ... |
| CVE-2024-43398 | MEDIUM | 5.9 | 1.2% | Aug 22, 2024 | REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many... |
| CVE-2024-36445 | CRITICAL | 9.8 | 1.0% | Aug 22, 2024 | Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication. |
| CVE-2024-36444 | HIGH | 8.1 | 0.5% | Aug 22, 2024 | cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device... |
| CVE-2024-36442 | HIGH | 8.8 | 0.7% | Aug 22, 2024 | cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrar... |
| CVE-2024-36440 | MEDIUM | 6.8 | 0.3% | Aug 22, 2024 | An issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may ... |
| CVE-2024-36439 | CRITICAL | 9.4 | 0.9% | Aug 22, 2024 | Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the dev... |
| CVE-2024-36443 | HIGH | 7.6 | 0.6% | Aug 22, 2024 | Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonym... |
| CVE-2024-43331 | CRITICAL | 9.8 | 0.4% | Aug 22, 2024 | Missing Authorization vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.9.3. |
| CVE-2024-7848 | MEDIUM | 6.5 | 0.3% | Aug 22, 2024 | The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Refe... |
| CVE-2024-39746 | MEDIUM | 5.9 | 0.3% | Aug 22, 2024 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive inform... |
| CVE-2024-39745 | HIGH | 7.5 | 0.3% | Aug 22, 2024 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that ... |
| CVE-2024-39744 | MEDIUM | 4.3 | 0.2% | Aug 22, 2024 | IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 is vulnerable to cross-site request forgery which could ... |
| CVE-2024-35151 | MEDIUM | 6.5 | 0.4% | Aug 22, 2024 | IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper a... |
| CVE-2024-7778 | MEDIUM | 5.4 | 0.3% | Aug 22, 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all... |
| CVE-2024-6870 | MEDIUM | 5.4 | 0.3% | Aug 22, 2024 | The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in ... |
| CVE-2024-8072 | MEDIUM | 5.3 | 0.6% | Aug 22, 2024 | Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users |
| CVE-2024-8071 | HIGH | 7.2 | 0.3% | Aug 22, 2024 | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can... |
| CVE-2024-43813 | MEDIUM | 4.3 | 0.2% | Aug 22, 2024 | Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticat... |
| CVE-2024-42411 | MEDIUM | 5.3 | 0.3% | Aug 22, 2024 | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST ... |
| CVE-2024-40886 | HIGH | 8.8 | 0.2% | Aug 22, 2024 | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the... |
| CVE-2024-39836 | MEDIUM | 6.5 | 0.3% | Aug 22, 2024 | Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synt... |
| CVE-2024-39810 | MEDIUM | 4.9 | 0.5% | Aug 22, 2024 | Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the Elasti... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now