2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42613 | HIGH | 8.8 | 0.3% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.ph... |
| CVE-2024-42611 | HIGH | 8.8 | 0.3% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/admin_page.php?link_id=1&mode=d... |
| CVE-2024-42610 | HIGH | 8.8 | 0.3% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php... |
| CVE-2024-42609 | HIGH | 8.8 | 0.2% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php... |
| CVE-2024-42607 | HIGH | 8.8 | 0.3% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php... |
| CVE-2024-42606 | HIGH | 8.8 | 0.2% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?cl... |
| CVE-2024-42605 | HIGH | 8.8 | 0.2% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/edit_page.php?li... |
| CVE-2024-42604 | HIGH | 8.8 | 0.3% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_group.php?... |
| CVE-2024-42603 | HIGH | 8.8 | 0.2% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php... |
| CVE-2024-42369 | MEDIUM | 5.3 | 0.5% | Aug 20, 2024 | matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room o... |
| CVE-2024-39690 | HIGH | 8.8 | 0.5% | Aug 20, 2024 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner ca... |
| CVE-2024-35540 | CRITICAL | 9 | 2.7% | Aug 20, 2024 | A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or... |
| CVE-2024-30949 | CRITICAL | 9.8 | 0.8% | Aug 20, 2024 | An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday f... |
| CVE-2024-8005 | CRITICAL | 9.8 | 0.7% | Aug 20, 2024 | A vulnerability was found in demozx gf_cms 1.0/1.0.1. It has been classified as critical. This affects the function init... |
| CVE-2024-8003 | CRITICAL | 9.8 | 0.8% | Aug 20, 2024 | A vulnerability was found in Go-Tribe gotribe-admin 1.0 and classified as problematic. Affected by this issue is the fun... |
| CVE-2024-6379 | MEDIUM | 6.1 | 0.2% | Aug 20, 2024 | A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release... |
| CVE-2024-6378 | MEDIUM | 5.4 | 0.3% | Aug 20, 2024 | A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEX... |
| CVE-2024-6377 | MEDIUM | 6.1 | 0.3% | Aug 20, 2024 | An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPER... |
| CVE-2024-42608 | HIGH | 8.8 | 0.3% | Aug 20, 2024 | Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/submit_page.php. |
| CVE-2024-42006 | HIGH | 7.5 | 0.4% | Aug 20, 2024 | Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure. |
| CVE-2024-39094 | MEDIUM | 5.4 | 0.3% | Aug 20, 2024 | Friendica 2024.03 is vulnerable to Cross Site Scripting (XSS) in settings/profile via the homepage, xmpp, and matrix par... |
| CVE-2024-34458 | HIGH | 7.5 | 0.4% | Aug 20, 2024 | Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information d... |
| CVE-2024-33872 | CRITICAL | 9.8 | 0.5% | Aug 20, 2024 | Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code executio... |
| CVE-2024-6918 | HIGH | 7.5 | 0.5% | Aug 20, 2024 | CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause a ... |
| CVE-2024-42586 | HIGH | 8.8 | 0.3% | Aug 20, 2024 | A Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now