2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41710 | HIGH | 7.2 | 41.6% | Aug 12, 2024 | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, ... |
| CVE-2024-40893 | MEDIUM | 6.8 | 1.6% | Aug 12, 2024 | Multiple authenticated operating system (OS) command injection vulnerabilities exist in Firewalla Box Software versions... |
| CVE-2024-40892 | HIGH | 7.1 | 0.9% | Aug 12, 2024 | A weak credential vulnerability exists in Firewalla Box Software versions before 1.979. This vulnerability allows a phys... |
| CVE-2024-42545 | CRITICAL | 9.8 | 0.7% | Aug 12, 2024 | TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg functio... |
| CVE-2024-42543 | CRITICAL | 9.8 | 0.7% | Aug 12, 2024 | TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth f... |
| CVE-2024-7700 | MEDIUM | 6.5 | 0.8% | Aug 12, 2024 | A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packag... |
| CVE-2024-42627 | HIGH | 8.8 | 0.3% | Aug 12, 2024 | FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/delete/3... |
| CVE-2024-42626 | HIGH | 8.8 | 0.3% | Aug 12, 2024 | FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/add. |
| CVE-2024-42625 | HIGH | 8.8 | 0.2% | Aug 12, 2024 | FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/add |
| CVE-2024-42624 | HIGH | 8.8 | 0.3% | Aug 12, 2024 | FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/delete/10. |
| CVE-2024-42623 | HIGH | 8.8 | 0.3% | Aug 12, 2024 | FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1 |
| CVE-2024-42474 | MEDIUM | 6.5 | 0.6% | Aug 12, 2024 | Streamlit is a data oriented application development framework for python. Snowflake Streamlit open source addressed a s... |
| CVE-2024-41651 | HIGH | 8.1 | 1.3% | Aug 12, 2024 | An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade func... |
| CVE-2024-41475 | HIGH | 8.8 | 0.3% | Aug 12, 2024 | Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration. |
| CVE-2024-40500 | HIGH | 8.6 | 0.6% | Aug 12, 2024 | Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute ar... |
| CVE-2024-42632 | HIGH | 8.8 | 0.3% | Aug 12, 2024 | FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/add. |
| CVE-2024-42631 | HIGH | 8.8 | 0.3% | Aug 12, 2024 | FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1. |
| CVE-2024-42630 | HIGH | 8.8 | 0.3% | Aug 12, 2024 | FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_mana... |
| CVE-2024-42629 | HIGH | 8.8 | 0.2% | Aug 12, 2024 | FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10. |
| CVE-2024-42628 | HIGH | 8.8 | 0.3% | Aug 12, 2024 | FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/edit/3. |
| CVE-2024-42489 | HIGH | 8.8 | 1.1% | Aug 12, 2024 | Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the... |
| CVE-2024-42485 | HIGH | 7.5 | 0.6% | Aug 12, 2024 | Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` all... |
| CVE-2024-42482 | MEDIUM | 6.5 | 0.8% | Aug 12, 2024 | fish-shop/syntax-check is a GitHub action for syntax checking fish shell files. Improper neutralization of delimiters in... |
| CVE-2024-42481 | HIGH | 7.5 | 0.5% | Aug 12, 2024 | Skyport Daemon (skyportd) is the daemon for the Skyport Panel. By making thousands of folders & files (easy due to skypo... |
| CVE-2024-42480 | CRITICAL | 9.9 | 0.6% | Aug 12, 2024 | Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the to... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now