2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33893 | MEDIUM | 6.1 | 0.7% | Aug 2, 2024 | Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displayin... |
| CVE-2024-33892 | HIGH | 7.5 | 0.4% | Aug 2, 2024 | Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s... |
| CVE-2024-7314 | CRITICAL | 9.8 | 51.5% | Aug 2, 2024 | anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can app... |
| CVE-2024-41519 | MEDIUM | 5.4 | 0.4% | Aug 2, 2024 | Feripro <= v2.2.3 is vulnerable to Cross Site Scripting (XSS) via "/admin/programm/<program_id>/zuordnung/veranstaltunge... |
| CVE-2024-41518 | HIGH | 7.5 | 0.7% | Aug 2, 2024 | An Incorrect Access Control vulnerability in "/admin/programm/<program_id>/export/statistics" in Feripro <= v2.2.3 allow... |
| CVE-2024-41517 | MEDIUM | 5.3 | 0.6% | Aug 2, 2024 | An Incorrect Access Control vulnerability in "/admin/benutzer/institution/rechteverwaltung/uebersicht" in Feripro <= v2.... |
| CVE-2024-41310 | HIGH | 7.5 | 0.8% | Aug 2, 2024 | AndServer 2.1.12 is vulnerable to Directory Traversal. |
| CVE-2024-7029 | CRITICAL | 9.8 | 39.0% | Aug 2, 2024 | Commands can be injected over the network and executed without authentication. |
| CVE-2024-41127 | CRITICAL | 9.6 | 0.8% | Aug 2, 2024 | Monkeytype is a minimalistic and customizable typing test. Monkeytype is vulnerable to Poisoned Pipeline Execution throu... |
| CVE-2024-38890 | HIGH | 8.4 | 0.2% | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later version... |
| CVE-2024-7323 | MEDIUM | 6.5 | 0.6% | Aug 2, 2024 | Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately fi... |
| CVE-2024-7204 | MEDIUM | 6.1 | 0.3% | Aug 2, 2024 | Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into... |
| CVE-2024-6704 | MEDIUM | 6.1 | 0.5% | Aug 2, 2024 | The Comments – wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.2... |
| CVE-2024-40723 | MEDIUM | 4.3 | 0.5% | Aug 2, 2024 | The specific API in HWATAIServiSign Windows Version from CHANGING Information Technology does not properly validate the ... |
| CVE-2024-40722 | MEDIUM | 4.3 | 0.5% | Aug 2, 2024 | The specific API in TCBServiSign Windows Version from CHANGING Information Technology does does not properly validate th... |
| CVE-2024-40721 | HIGH | 8.8 | 0.5% | Aug 2, 2024 | The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-... |
| CVE-2024-40720 | HIGH | 8.8 | 0.6% | Aug 2, 2024 | The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-... |
| CVE-2024-38879 | CRITICAL | 9.8 | 0.8% | Aug 2, 2024 | A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (A... |
| CVE-2024-38878 | MEDIUM | 6.5 | 11.5% | Aug 2, 2024 | A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (A... |
| CVE-2024-38877 | HIGH | 8.8 | 0.2% | Aug 2, 2024 | A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Cont... |
| CVE-2024-38876 | HIGH | 7.8 | 0.2% | Aug 2, 2024 | A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Cont... |
| CVE-2024-4643 | MEDIUM | 5.4 | 0.4% | Aug 2, 2024 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W... |
| CVE-2024-40719 | MEDIUM | 6.5 | 0.2% | Aug 2, 2024 | The encryption strength of the authorization keys in CHANGING Information Technology TCBServiSign Windows Version is ins... |
| CVE-2024-36268 | CRITICAL | 9.8 | 1.2% | Aug 2, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InL... |
| CVE-2024-27182 | MEDIUM | 4.9 | 0.7% | Aug 2, 2024 | In Apache Linkis <= 1.5.0, Arbitrary file deletion in Basic management services on A user with an administrator accou... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now