2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31842 | HIGH | 8.8 | 0.4% | Aug 20, 2024 | An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user ... |
| CVE-2024-42619 | HIGH | 8.8 | 0.2% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_managemen... |
| CVE-2024-38175 | HIGH | 8.8 | 0.8% | Aug 20, 2024 | An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated atta... |
| CVE-2024-6322 | MEDIUM | 5.4 | 0.3% | Aug 20, 2024 | Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user... |
| CVE-2024-42612 | HIGH | 8.8 | 0.3% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_managemen... |
| CVE-2024-35214 | HIGH | 7.1 | 0.2% | Aug 20, 2024 | A tampering vulnerability in the CylanceOPTICS Windows Installer Package of CylanceOPTICS for Windows version 3.2 and 3.... |
| CVE-2024-43408 | MEDIUM | 6.3 | 0.2% | Aug 20, 2024 | Discourse Placeholder Forms will let you build dynamic documentation. Unsanitized and stored user input was injected in ... |
| CVE-2024-42919 | CRITICAL | 9.8 | 1.0% | Aug 20, 2024 | eScan Management Console 14.0.1400.2281 is vulnerable to Incorrect Access Control via acteScanAVReport. |
| CVE-2024-42598 | MEDIUM | 6.7 | 1.2% | Aug 20, 2024 | SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplay... |
| CVE-2024-40743 | MEDIUM | 6.1 | 0.3% | Aug 20, 2024 | The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors. |
| CVE-2024-27187 | HIGH | 7.5 | 0.4% | Aug 20, 2024 | Improper Access Controls allows backend users to overwrite their username when disallowed. |
| CVE-2024-27186 | MEDIUM | 6.1 | 0.3% | Aug 20, 2024 | The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions. |
| CVE-2024-27185 | CRITICAL | 9.1 | 0.4% | Aug 20, 2024 | The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors. |
| CVE-2024-27184 | MEDIUM | 6.1 | 0.2% | Aug 20, 2024 | Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.. |
| CVE-2024-43409 | MEDIUM | 6.5 | 0.3% | Aug 20, 2024 | Ghost is a Node.js content management system. Improper authentication on some endpoints used for member actions would al... |
| CVE-2024-43406 | HIGH | 8.8 | 0.9% | Aug 20, 2024 | LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge dev... |
| CVE-2024-43404 | CRITICAL | 9.8 | 1.1% | Aug 20, 2024 | MEGABOT is a fully customized Discord bot for learning and fun. The `/math` command and functionality of MEGABOT version... |
| CVE-2024-43397 | MEDIUM | 4.3 | 0.3% | Aug 20, 2024 | Apollo is a configuration management system. A vulnerability exists in the synchronization configuration feature that al... |
| CVE-2024-43377 | MEDIUM | 4.3 | 0.2% | Aug 20, 2024 | Umbraco CMS is an ASP.NET CMS. An authenticated user can access a few unintended endpoints. This issue is fixed in 14.1.... |
| CVE-2024-43376 | MEDIUM | 5.3 | 0.4% | Aug 20, 2024 | Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is... |
| CVE-2024-42662 | HIGH | 7.5 | 0.5% | Aug 20, 2024 | An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request. |
| CVE-2024-42621 | HIGH | 8.8 | 0.3% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php |
| CVE-2024-42618 | HIGH | 8.8 | 0.3% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /module.php?module=karm... |
| CVE-2024-42617 | HIGH | 8.8 | 0.3% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_config.php... |
| CVE-2024-42616 | HIGH | 8.8 | 0.3% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.ph... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now