2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41119 | CRITICAL | 9.8 | 1.4% | Jul 26, 2024 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb... |
| CVE-2024-41118 | CRITICAL | 9.8 | 0.7% | Jul 26, 2024 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb... |
| CVE-2024-41117 | CRITICAL | 9.8 | 1.3% | Jul 26, 2024 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb... |
| CVE-2024-41116 | CRITICAL | 9.8 | 1.3% | Jul 26, 2024 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb... |
| CVE-2024-41115 | CRITICAL | 9.8 | 1.5% | Jul 26, 2024 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb... |
| CVE-2024-41114 | CRITICAL | 9.8 | 1.4% | Jul 26, 2024 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb... |
| CVE-2024-4786 | LOW | 2.8 | 0.1% | Jul 26, 2024 | An improper validation vulnerability was reported in the Lenovo Tab K10 that could allow a specially crafted application... |
| CVE-2024-41113 | CRITICAL | 9.8 | 1.4% | Jul 26, 2024 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb... |
| CVE-2024-41112 | CRITICAL | 9.8 | 1.4% | Jul 26, 2024 | streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb... |
| CVE-2024-40117 | CRITICAL | 9.8 | 0.7% | Jul 26, 2024 | Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrat... |
| CVE-2024-40116 | HIGH | 8.1 | 0.4% | Jul 26, 2024 | An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the expo... |
| CVE-2024-38512 | HIGH | 7.2 | 1.0% | Jul 26, 2024 | A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated priv... |
| CVE-2024-38511 | HIGH | 7.2 | 1.0% | Jul 26, 2024 | A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an aut... |
| CVE-2024-38510 | HIGH | 7.2 | 1.1% | Jul 26, 2024 | A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authe... |
| CVE-2024-38509 | HIGH | 7.2 | 0.5% | Jul 26, 2024 | A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated priv... |
| CVE-2024-38508 | HIGH | 7.2 | 1.0% | Jul 26, 2024 | A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC t... |
| CVE-2024-42007 | MEDIUM | 5.8 | 0.6% | Jul 26, 2024 | SPX (aka php-spx) through 0.4.15 allows SPX_UI_URI Directory Traversal to read arbitrary files. |
| CVE-2024-39304 | HIGH | 8.8 | 3.0% | Jul 26, 2024 | ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an au... |
| CVE-2024-38872 | HIGH | 8.8 | 3.1% | Jul 26, 2024 | Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection i... |
| CVE-2024-38871 | HIGH | 8.8 | 3.1% | Jul 26, 2024 | Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection i... |
| CVE-2024-41813 | HIGH | 7.5 | 0.7% | Jul 26, 2024 | txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Starting ... |
| CVE-2024-41812 | HIGH | 7.5 | 0.7% | Jul 26, 2024 | txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Prior to ... |
| CVE-2024-41375 | MEDIUM | 6.1 | 0.3% | Jul 26, 2024 | ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/terminal-xhr.php |
| CVE-2024-41374 | MEDIUM | 6.1 | 0.3% | Jul 26, 2024 | ICEcoder 8.1 is vulnerable to Cross Site Scripting (XSS) via lib/settings-screen.php |
| CVE-2024-41373 | MEDIUM | 6.3 | 0.4% | Jul 26, 2024 | ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now