2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41162 | MEDIUM | 4.3 | 0.3% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification ... |
| CVE-2024-41144 | HIGH | 7.1 | 0.4% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced post... |
| CVE-2024-41123 | HIGH | 7.5 | 1.3% | Aug 1, 2024 | REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some DoS vulnerabilities when it parses an XML that has... |
| CVE-2024-39839 | MEDIUM | 4.3 | 0.3% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow users to set their o... |
| CVE-2024-39837 | MEDIUM | 5.4 | 0.3% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious r... |
| CVE-2024-39832 | HIGH | 8.7 | 0.5% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly safeguard an error h... |
| CVE-2024-39777 | CRITICAL | 9.6 | 0.4% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow unsolicited invit... |
| CVE-2024-39274 | MEDIUM | 6.5 | 0.3% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to properly validate that the... |
| CVE-2024-36492 | MEDIUM | 6.4 | 0.3% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to disallow the modification of ... |
| CVE-2024-29977 | MEDIUM | 4.3 | 0.3% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are ... |
| CVE-2024-7358 | HIGH | 8.5 | 0.2% | Aug 1, 2024 | A vulnerability was found in Point B Ltd Getscreen Agent 2.19.6 on Windows. It has been declared as critical. Affected b... |
| CVE-2024-6923 | MEDIUM | 5.5 | 0.7% | Aug 1, 2024 | There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email ... |
| CVE-2024-7357 | CRITICAL | 9.8 | 5.7% | Aug 1, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-600 up to 2.18. It has been rated as critical. T... |
| CVE-2024-2455 | MEDIUM | 5.4 | 0.3% | Aug 1, 2024 | The Element Pack - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2024-6346 | MEDIUM | 5.4 | 0.3% | Aug 1, 2024 | The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2024-38490 | MEDIUM | 4.4 | 0.2% | Aug 1, 2024 | Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local atta... |
| CVE-2024-38489 | MEDIUM | 4.4 | 0.2% | Aug 1, 2024 | Dell iDRAC Service Module version 5.3.0.0 and prior contains Out of bound write Vulnerability. A privileged local attack... |
| CVE-2024-38481 | MEDIUM | 4.4 | 0.2% | Aug 1, 2024 | Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attac... |
| CVE-2024-28972 | HIGH | 7.5 | 0.3% | Aug 1, 2024 | Dell InsightIQ, Verion 5.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthentica... |
| CVE-2024-25948 | MEDIUM | 4.4 | 0.2% | Aug 1, 2024 | Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local atta... |
| CVE-2024-7302 | MEDIUM | 5.4 | 0.4% | Aug 1, 2024 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2024-5678 | MEDIUM | 4.7 | 2.5% | Aug 1, 2024 | Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL ... |
| CVE-2024-5331 | MEDIUM | 4.3 | 0.2% | Aug 1, 2024 | The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1... |
| CVE-2024-5330 | MEDIUM | 5.4 | 0.2% | Aug 1, 2024 | The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the breakdance_css_file_paths_cache... |
| CVE-2024-25947 | MEDIUM | 4.4 | 0.2% | Aug 1, 2024 | Dell iDRAC Service Module version 5.3.0.0 and prior, contain an Out of bound Read Vulnerability. A privileged local atta... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now