2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7540 | LOW | 3.3 | 0.3% | Aug 6, 2024 | oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attac... |
| CVE-2024-7539 | HIGH | 7.8 | 0.3% | Aug 6, 2024 | oFono CUSD Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execut... |
| CVE-2024-7538 | HIGH | 7.8 | 0.3% | Aug 6, 2024 | oFono CUSD AT Command Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attacker... |
| CVE-2024-7537 | MEDIUM | 5.5 | 0.3% | Aug 6, 2024 | oFono QMI SMS Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attacker... |
| CVE-2024-7494 | CRITICAL | 9.8 | 0.6% | Aug 5, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Clinics Patient Management System 1.... |
| CVE-2024-42352 | HIGH | 7.5 | 0.6% | Aug 5, 2024 | Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. `nuxt/icon` pro... |
| CVE-2024-41811 | LOW | 3.9 | 0.2% | Aug 5, 2024 | ipl/web is a set of common web components for php projects. Some of the recent development by Icinga is, under certain c... |
| CVE-2024-34344 | HIGH | 8.8 | 0.8% | Aug 5, 2024 | Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insu... |
| CVE-2024-34343 | MEDIUM | 6.1 | 0.4% | Aug 5, 2024 | Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. The `navigateTo... |
| CVE-2024-23657 | HIGH | 8.8 | 1.1% | Aug 5, 2024 | Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools i... |
| CVE-2024-6915 | CRITICAL | 9.3 | 0.6% | Aug 5, 2024 | JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to... |
| CVE-2024-42350 | LOW | 3 | 0.3% | Aug 5, 2024 | Biscuit is an authorization token with decentralized verification, offline attenuation and strong security policy enforc... |
| CVE-2024-41960 | MEDIUM | 4.8 | 0.3% | Aug 5, 2024 | mailcow: dockerized is an open source groupware/email suite based on docker. An authenticated admin user can inject a Ja... |
| CVE-2024-41959 | MEDIUM | 6.1 | 0.3% | Aug 5, 2024 | mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a Ja... |
| CVE-2024-41958 | HIGH | 7.2 | 1.0% | Aug 5, 2024 | mailcow: dockerized is an open source groupware/email suite based on docker. A vulnerability has been discovered in the ... |
| CVE-2024-41820 | MEDIUM | 6 | 0.4% | Aug 5, 2024 | Kubean is a cluster lifecycle management toolchain based on kubespray and other cluster LCM engine. The ClusterRole has ... |
| CVE-2024-41816 | MEDIUM | 5.4 | 0.4% | Aug 5, 2024 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scriptin... |
| CVE-2024-6361 | MEDIUM | 5.4 | 0.2% | Aug 5, 2024 | Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane. The vulnerability affects all v... |
| CVE-2024-42010 | HIGH | 7.5 | 52.8% | Aug 5, 2024 | mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) to... |
| CVE-2024-42009 | CRITICAL | 9.3 | 82.9% | Aug 5, 2024 | A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea... |
| CVE-2024-42008 | CRITICAL | 9.3 | 32.3% | Aug 5, 2024 | A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7... |
| CVE-2024-41381 | MEDIUM | 6.1 | 0.3% | Aug 5, 2024 | microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\ad... |
| CVE-2024-41380 | MEDIUM | 6.1 | 0.3% | Aug 5, 2024 | microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_ta... |
| CVE-2024-41376 | HIGH | 8.8 | 1.0% | Aug 5, 2024 | dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php. |
| CVE-2024-41200 | MEDIUM | 5.5 | 0.2% | Aug 5, 2024 | A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now