2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42473 | CRITICAL | 9.8 | 0.5% | Aug 12, 2024 | OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when cal... |
| CVE-2024-42470 | CRITICAL | 9.1 | 0.5% | Aug 12, 2024 | openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. S... |
| CVE-2024-42469 | CRITICAL | 9.8 | 1.2% | Aug 12, 2024 | openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. P... |
| CVE-2024-42468 | HIGH | 7.5 | 0.8% | Aug 12, 2024 | openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. C... |
| CVE-2024-42467 | CRITICAL | 10 | 1.0% | Aug 12, 2024 | openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. I... |
| CVE-2024-42370 | HIGH | 8.3 | 0.6% | Aug 12, 2024 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-pr... |
| CVE-2024-42367 | MEDIUM | 4.8 | 0.6% | Aug 12, 2024 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior to ... |
| CVE-2024-42167 | HIGH | 7.2 | 0.5% | Aug 12, 2024 | The function "generate_app_certificates" in controllers/saml2/saml2.js of FIWARE Keyrock <= 8.4 does not neutralize spec... |
| CVE-2024-42166 | HIGH | 7.2 | 0.5% | Aug 12, 2024 | The function "generate_app_certificates" in lib/app_certificates.js of FIWARE Keyrock <= 8.4 does not neutralize special... |
| CVE-2024-42165 | MEDIUM | 5.4 | 0.4% | Aug 12, 2024 | Insufficiently random values for generating activation token in FIWARE Keyrock <= 8.4 allow attackers to activate accoun... |
| CVE-2024-42164 | MEDIUM | 4.3 | 0.4% | Aug 12, 2024 | Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two... |
| CVE-2024-42163 | HIGH | 8.1 | 0.3% | Aug 12, 2024 | Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to take over t... |
| CVE-2024-42001 | CRITICAL | 9.8 | 0.7% | Aug 12, 2024 | An improper authentication vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeate... |
| CVE-2024-41936 | HIGH | 7.5 | 1.7% | Aug 12, 2024 | A directory traversal vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software v... |
| CVE-2024-41890 | MEDIUM | 5.3 | 1.1% | Aug 12, 2024 | Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: ... |
| CVE-2024-41888 | MEDIUM | 5.3 | 1.2% | Aug 12, 2024 | Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: ... |
| CVE-2024-41577 | CRITICAL | 9.8 | 1.0% | Aug 12, 2024 | An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arb... |
| CVE-2024-41570 | CRITICAL | 9.8 | 2.9% | Aug 12, 2024 | An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send... |
| CVE-2024-41482 | MEDIUM | 6.1 | 0.3% | Aug 12, 2024 | Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component. |
| CVE-2024-41481 | MEDIUM | 6.1 | 0.4% | Aug 12, 2024 | Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component. |
| CVE-2024-41476 | CRITICAL | 9.8 | 0.6% | Aug 12, 2024 | AMTT Hotel Broadband Operation System (HiBOS) V3.0.3.151204 and before is vulnerable to SQL Injection via /manager/card/... |
| CVE-2024-41332 | MEDIUM | 6.5 | 0.6% | Aug 12, 2024 | Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 al... |
| CVE-2024-40488 | HIGH | 8.8 | 0.3% | Aug 12, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lea... |
| CVE-2024-40487 | HIGH | 7.6 | 1.1% | Aug 12, 2024 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0... |
| CVE-2024-40486 | CRITICAL | 9.8 | 1.0% | Aug 12, 2024 | A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execut... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now