2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41172 | HIGH | 7.5 | 1.2% | Jul 19, 2024 | In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit ... |
| CVE-2024-39457 | MEDIUM | 5.4 | 0.2% | Jul 19, 2024 | Cybozu Garoon 6.0.0 to 6.0.1 contains a cross-site scripting vulnerability in PDF preview. If this vulnerability is expl... |
| CVE-2024-32007 | HIGH | 7.5 | 1.3% | Jul 19, 2024 | An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an at... |
| CVE-2024-29736 | CRITICAL | 9.1 | 1.0% | Jul 19, 2024 | A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attac... |
| CVE-2024-6903 | HIGH | 8.8 | 0.5% | Jul 19, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Record Management System 1.0. Affect... |
| CVE-2024-6902 | HIGH | 8.8 | 0.5% | Jul 19, 2024 | A vulnerability classified as critical was found in SourceCodester Record Management System 1.0. Affected by this vulner... |
| CVE-2024-6799 | MEDIUM | 4.3 | 0.3% | Jul 19, 2024 | The YITH Essential Kit for WooCommerce #1 plugin for WordPress is vulnerable to unauthorized modification of data due to... |
| CVE-2024-6338 | HIGH | 8.8 | 0.5% | Jul 19, 2024 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ paramete... |
| CVE-2024-40724 | HIGH | 7.8 | 0.3% | Jul 19, 2024 | Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.2 allows a local attacker to execute arbitrary ... |
| CVE-2024-6901 | HIGH | 8.8 | 0.5% | Jul 19, 2024 | A vulnerability classified as critical has been found in SourceCodester Record Management System 1.0. Affected is an unk... |
| CVE-2024-6900 | HIGH | 8.8 | 0.5% | Jul 19, 2024 | A vulnerability was found in SourceCodester Record Management System 1.0. It has been rated as critical. This issue affe... |
| CVE-2024-6205 | CRITICAL | 9.8 | 4.2% | Jul 19, 2024 | The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using... |
| CVE-2024-5604 | MEDIUM | 5.9 | 0.3% | Jul 19, 2024 | The Bug Library WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-6899 | CRITICAL | 9.8 | 0.6% | Jul 19, 2024 | A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as critical. This vulnera... |
| CVE-2024-21583 | MEDIUM | 4.1 | 0.6% | Jul 19, 2024 | Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the ... |
| CVE-2024-21527 | HIGH | 8.2 | 0.6% | Jul 19, 2024 | Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com... |
| CVE-2024-6898 | CRITICAL | 9.8 | 0.6% | Jul 19, 2024 | A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as critical. This affec... |
| CVE-2024-38156 | MEDIUM | 6.1 | 0.4% | Jul 19, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-35199 | HIGH | 8.2 | 0.6% | Jul 19, 2024 | TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. In affected versions... |
| CVE-2024-35198 | CRITICAL | 9.8 | 0.8% | Jul 19, 2024 | TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. TorchServe 's check ... |
| CVE-2024-30130 | HIGH | 7.5 | 0.3% | Jul 19, 2024 | HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an a... |
| CVE-2024-41111 | HIGH | 7.2 | 0.7% | Jul 18, 2024 | Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all s... |
| CVE-2024-40642 | HIGH | 8.1 | 0.7% | Jul 18, 2024 | The netty incubator codec.bhttp is a java language binary http parser. In affected versions the `BinaryHttpParser` class... |
| CVE-2024-5997 | MEDIUM | 4.3 | 0.4% | Jul 18, 2024 | The Duplica – Duplicate Posts, Pages, Custom Posts or Users plugin for WordPress is vulnerable to unauthorized modificat... |
| CVE-2024-6455 | MEDIUM | 5.3 | 0.4% | Jul 18, 2024 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now