2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6978 | HIGH | 8.8 | 0.1% | Jul 31, 2024 | Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP... |
| CVE-2024-6977 | MEDIUM | 6.5 | 0.2% | Jul 31, 2024 | A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, ... |
| CVE-2024-6975 | HIGH | 8.8 | 0.3% | Jul 31, 2024 | Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Clien... |
| CVE-2024-6974 | HIGH | 7.8 | 0.2% | Jul 31, 2024 | Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.3... |
| CVE-2024-6973 | HIGH | 8.8 | 0.8% | Jul 31, 2024 | Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34. |
| CVE-2024-41953 | MEDIUM | 6.1 | 0.6% | Jul 31, 2024 | Zitadel is an open source identity management system. ZITADEL uses HTML for emails and renders certain information such ... |
| CVE-2024-41952 | MEDIUM | 5.3 | 0.6% | Jul 31, 2024 | Zitadel is an open source identity management system. ZITADEL administrators can enable a setting called "Ignoring unkno... |
| CVE-2024-41950 | HIGH | 7.5 | 1.2% | Jul 31, 2024 | Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models, vecto... |
| CVE-2024-41947 | MEDIUM | 5.4 | 1.6% | Jul 31, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a c... |
| CVE-2024-39694 | MEDIUM | 4.7 | 0.5% | Jul 31, 2024 | Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to c... |
| CVE-2024-39318 | MEDIUM | 5.4 | 0.4% | Jul 31, 2024 | The Ibexa Admin UI Bundle contains all the necessary parts to run the Ibexa DXP Back Office interface. The file upload w... |
| CVE-2024-37901 | HIGH | 8.8 | 1.1% | Jul 31, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with e... |
| CVE-2024-37900 | MEDIUM | 4.6 | 14.8% | Jul 31, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading ... |
| CVE-2024-37898 | MEDIUM | 4.3 | 0.4% | Jul 31, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has... |
| CVE-2024-7340 | HIGH | 8.8 | 5.0% | Jul 31, 2024 | The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation... |
| CVE-2024-3083 | HIGH | 8.3 | 0.2% | Jul 31, 2024 | A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations... |
| CVE-2024-3082 | MEDIUM | 4.6 | 0.1% | Jul 31, 2024 | A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical acces... |
| CVE-2024-37135 | MEDIUM | 4.4 | 0.1% | Jul 31, 2024 | DM5500 5.16.0.0, contains an information disclosure vulnerability. A local attacker with high privileges could potential... |
| CVE-2024-31203 | MEDIUM | 5.5 | 0.1% | Jul 31, 2024 | A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer al... |
| CVE-2024-31202 | HIGH | 7.8 | 0.2% | Jul 31, 2024 | A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a loca... |
| CVE-2024-31201 | MEDIUM | 6.7 | 0.2% | Jul 31, 2024 | A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be... |
| CVE-2024-31200 | MEDIUM | 4.6 | 0.2% | Jul 31, 2024 | A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker w... |
| CVE-2024-31199 | MEDIUM | 6.1 | 0.3% | Jul 31, 2024 | A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users ... |
| CVE-2024-6208 | MEDIUM | 5.4 | 0.4% | Jul 31, 2024 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packag... |
| CVE-2024-39379 | MEDIUM | 5.5 | 0.3% | Jul 31, 2024 | Acrobat for Edge versions 126.0.2592.81 and earlier are affected by an out-of-bounds read vulnerability that could lead ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now