2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7276 | HIGH | 7.2 | 0.6% | Jul 30, 2024 | A vulnerability has been found in itsourcecode Alton Management System 1.0 and classified as critical. Affected by this ... |
| CVE-2024-7275 | HIGH | 7.2 | 0.6% | Jul 30, 2024 | A vulnerability, which was classified as critical, was found in itsourcecode Alton Management System 1.0. Affected is an... |
| CVE-2024-7274 | HIGH | 7.2 | 0.6% | Jul 30, 2024 | A vulnerability, which was classified as critical, has been found in itsourcecode Alton Management System 1.0. This issu... |
| CVE-2024-37281 | MEDIUM | 6.5 | 0.4% | Jul 30, 2024 | An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to crash by sending a larg... |
| CVE-2024-7273 | CRITICAL | 9.8 | 0.7% | Jul 30, 2024 | A vulnerability classified as critical was found in itsourcecode Alton Management System 1.0. This vulnerability affects... |
| CVE-2024-5901 | MEDIUM | 5.4 | 0.4% | Jul 30, 2024 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widge... |
| CVE-2024-38983 | CRITICAL | 9.8 | 1.0% | Jul 30, 2024 | Prototype Pollution in alykoshin mini-deep-assign v0.0.8 allows an attacker to execute arbitrary code or cause a Denial ... |
| CVE-2024-41945 | LOW | 3.1 | 0.3% | Jul 30, 2024 | fuels-ts is a library for interacting with Fuel v2. The typescript SDK has no awareness of to-be-spent transactions cau... |
| CVE-2024-41611 | CRITICAL | 9.8 | 0.8% | Jul 30, 2024 | In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers ... |
| CVE-2024-41610 | CRITICAL | 9.8 | 0.9% | Jul 30, 2024 | D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attacker... |
| CVE-2024-39012 | CRITICAL | 9.8 | 1.0% | Jul 30, 2024 | ais-ltd strategyen v0.4.0 was discovered to contain a prototype pollution via the function mergeObjects. This vulnerabil... |
| CVE-2024-39011 | CRITICAL | 9.8 | 0.9% | Jul 30, 2024 | Prototype Pollution in chargeover redoc v2.0.9-rc.69 allows attackers to execute arbitrary code or cause a Denial of Ser... |
| CVE-2024-39010 | CRITICAL | 9.8 | 0.9% | Jul 30, 2024 | chase-moskal snapstate v0.0.9 was discovered to contain a prototype pollution via the function attemptNestedProperty. Th... |
| CVE-2024-38986 | CRITICAL | 9.8 | 1.0% | Jul 30, 2024 | Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (Do... |
| CVE-2024-38984 | CRITICAL | 9.8 | 1.0% | Jul 30, 2024 | Prototype Pollution in lukebond json-override 0.2.0 allows attackers to to execute arbitrary code or cause a Denial of S... |
| CVE-2024-36572 | CRITICAL | 9.8 | 0.7% | Jul 30, 2024 | Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the ... |
| CVE-2024-5250 | MEDIUM | 5.3 | 0.3% | Jul 30, 2024 | In versions of Akana API Platform prior to 2024.1.0 overly verbose errors can be found in SAML integrations |
| CVE-2024-5249 | HIGH | 7.5 | 0.2% | Jul 30, 2024 | In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed. |
| CVE-2024-41443 | MEDIUM | 5.5 | 0.4% | Jul 30, 2024 | A stack overflow in the function cp_dynamic() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial ... |
| CVE-2024-41440 | MEDIUM | 6.2 | 0.8% | Jul 30, 2024 | A heap buffer overflow in the function png_quantize() of hicolor v0.5.0 allows attackers to cause a Denial of Service (D... |
| CVE-2024-41439 | MEDIUM | 5.5 | 0.4% | Jul 30, 2024 | A heap buffer overflow in the function cp_block() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Den... |
| CVE-2024-41438 | MEDIUM | 6.2 | 0.8% | Jul 30, 2024 | A heap buffer overflow in the function cp_stored() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a De... |
| CVE-2024-41437 | MEDIUM | 5.5 | 0.4% | Jul 30, 2024 | A heap buffer overflow in the function cp_unfilter() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a ... |
| CVE-2024-3930 | CRITICAL | 9.8 | 0.3% | Jul 30, 2024 | In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered. |
| CVE-2024-41943 | MEDIUM | 4.6 | 0.3% | Jul 30, 2024 | I, Librarian is an open-source version of a PDF managing SaaS. PDF notes are displayed on the Item Summary page without ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now