2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41808 | MEDIUM | 5.4 | 0.6% | Jul 25, 2024 | The OpenObserve open-source observability platform provides the ability to filter logs in a dashboard by the values uplo... |
| CVE-2024-40324 | MEDIUM | 5.4 | 0.6% | Jul 25, 2024 | A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) charac... |
| CVE-2024-38289 | CRITICAL | 9.8 | 40.9% | Jul 25, 2024 | A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x all... |
| CVE-2024-38288 | HIGH | 7.2 | 3.2% | Jul 25, 2024 | A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allow... |
| CVE-2024-38287 | CRITICAL | 9.8 | 0.5% | Jul 25, 2024 | The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticat... |
| CVE-2024-29069 | HIGH | 7.3 | 0.2% | Jul 25, 2024 | In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap... |
| CVE-2024-29068 | MEDIUM | 6.6 | 0.2% | Jul 25, 2024 | In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is... |
| CVE-2024-40318 | HIGH | 7.2 | 1.2% | Jul 25, 2024 | An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploadi... |
| CVE-2024-1724 | HIGH | 8.2 | 0.3% | Jul 25, 2024 | In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict w... |
| CVE-2024-40873 | LOW | 3.4 | 0.3% | Jul 25, 2024 | There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prio... |
| CVE-2024-28772 | MEDIUM | 5.4 | 0.3% | Jul 25, 2024 | IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cros... |
| CVE-2024-7007 | CRITICAL | 9.8 | 0.6% | Jul 25, 2024 | Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an ... |
| CVE-2024-41801 | MEDIUM | 6.1 | 0.3% | Jul 25, 2024 | OpenProject is open source project management software. Prior to version 14.3.0, using a forged HOST header in the defau... |
| CVE-2024-41800 | HIGH | 7.5 | 0.4% | Jul 25, 2024 | Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity p... |
| CVE-2024-40872 | HIGH | 8.4 | 0.2% | Jul 25, 2024 | There is an elevation of privilege vulnerability in server and client components of Absolute Secure Access prior to vers... |
| CVE-2024-36542 | HIGH | 8.8 | 0.5% | Jul 25, 2024 | Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the s... |
| CVE-2024-7101 | HIGH | 7.3 | 0.5% | Jul 25, 2024 | A vulnerability, which was classified as critical, has been found in ForIP Tecnologia Administração PABX 1.x. This issue... |
| CVE-2024-41806 | MEDIUM | 5.3 | 0.3% | Jul 25, 2024 | The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information... |
| CVE-2024-36111 | MEDIUM | 6.3 | 8.4% | Jul 25, 2024 | KubePi is a K8s panel. Starting in version 1.6.3 and prior to version 1.8.0, there is a defect in the KubePi JWT token v... |
| CVE-2024-39674 | MEDIUM | 5.5 | 0.1% | Jul 25, 2024 | Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect ... |
| CVE-2024-39673 | HIGH | 7.1 | 0.1% | Jul 25, 2024 | Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vu... |
| CVE-2024-39672 | HIGH | 7.1 | 0.1% | Jul 25, 2024 | Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affe... |
| CVE-2024-39671 | MEDIUM | 5.5 | 0.1% | Jul 25, 2024 | Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability ... |
| CVE-2024-39670 | MEDIUM | 5.5 | 0.1% | Jul 25, 2024 | Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulner... |
| CVE-2024-6589 | HIGH | 8.8 | 0.8% | Jul 25, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now