2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32864 | HIGH | 8.1 | 0.2% | Aug 1, 2024 | Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS) |
| CVE-2024-32863 | HIGH | 8.8 | 0.2% | Aug 1, 2024 | Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF) |
| CVE-2024-7365 | CRITICAL | 9.8 | 0.6% | Aug 1, 2024 | A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0 and classified as critical. Affect... |
| CVE-2024-7364 | CRITICAL | 9.8 | 0.6% | Aug 1, 2024 | A vulnerability has been found in SourceCodester Tracking Monitoring Management System 1.0 and classified as critical. A... |
| CVE-2024-7363 | CRITICAL | 9.8 | 0.6% | Aug 1, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Tracking Monitoring Management System 1.0... |
| CVE-2024-7362 | CRITICAL | 9.8 | 0.6% | Aug 1, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Tracking Monitoring Management Syste... |
| CVE-2024-4353 | MEDIUM | 4.8 | 0.3% | Aug 1, 2024 | Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in the generate dashboard board ins... |
| CVE-2024-7361 | CRITICAL | 9.8 | 0.5% | Aug 1, 2024 | A vulnerability classified as critical was found in SourceCodester Tracking Monitoring Management System 1.0. This vulne... |
| CVE-2024-7360 | HIGH | 8.8 | 0.3% | Aug 1, 2024 | A vulnerability classified as problematic has been found in SourceCodester Tracking Monitoring Management System 1.0. Th... |
| CVE-2024-7256 | HIGH | 8.8 | 0.5% | Aug 1, 2024 | Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to exe... |
| CVE-2024-7255 | HIGH | 8.8 | 0.7% | Aug 1, 2024 | Out of bounds read in WebTransport in Google Chrome prior to 127.0.6533.88 allowed a remote attacker to potentially perf... |
| CVE-2024-6990 | HIGH | 8.8 | 0.9% | Aug 1, 2024 | Uninitialized Use in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to potentially pe... |
| CVE-2024-7359 | MEDIUM | 6.1 | 0.4% | Aug 1, 2024 | A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been rated as problematic.... |
| CVE-2024-7211 | MEDIUM | 6.1 | 0.2% | Aug 1, 2024 | The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulner... |
| CVE-2024-41962 | MEDIUM | 6.3 | 0.3% | Aug 1, 2024 | Bostr is an nostr relay aggregator proxy that acts like a regular nostr relay. bostr let everyone in even having authori... |
| CVE-2024-23600 | LOW | 2.7 | 0.7% | Aug 1, 2024 | Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a p... |
| CVE-2024-6873 | HIGH | 8.1 | 0.7% | Aug 1, 2024 | It is possible to crash or redirect the execution flow of the ClickHouse server process from an unauthenticated vector b... |
| CVE-2024-6242 | HIGH | 7.3 | 9.2% | Aug 1, 2024 | A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot f... |
| CVE-2024-6040 | HIGH | 8.8 | 0.2% | Aug 1, 2024 | In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multi... |
| CVE-2024-41265 | HIGH | 7.5 | 0.3% | Aug 1, 2024 | A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via t... |
| CVE-2024-41264 | HIGH | 7.5 | 0.5% | Aug 1, 2024 | An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostK... |
| CVE-2024-41260 | HIGH | 7.5 | 0.5% | Aug 1, 2024 | A static initialization vector (IV) in the encrypt function of netbird management's service from v0.23.2 to v0.29.1 allo... |
| CVE-2024-41961 | CRITICAL | 9.6 | 0.6% | Aug 1, 2024 | Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulner... |
| CVE-2024-41946 | HIGH | 7.5 | 1.2% | Aug 1, 2024 | REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulnerability when it parses an XML that has many entity... |
| CVE-2024-41926 | MEDIUM | 4.3 | 0.2% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the co... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now