2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39124 | MEDIUM | 5.4 | 0.3% | Jul 17, 2024 | In Roundup before 2.4.0, classhelpers (_generic.help.html) allow XSS. |
| CVE-2024-32981 | MEDIUM | 5.4 | 0.3% | Jul 17, 2024 | Silverstripe framework is the PHP framework forming the base for the Silverstripe CMS. In affected versions a bad actor ... |
| CVE-2024-29885 | MEDIUM | 4.3 | 0.4% | Jul 17, 2024 | silverstripe/reports is an API for creating backend reports in the Silverstripe Framework. In affected versions reports ... |
| CVE-2024-40420 | — | — | — | Jul 17, 2024 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-36694. Reason: This record is a duplicate of CVE-2024-... |
| CVE-2024-28796 | MEDIUM | 5.4 | 0.3% | Jul 17, 2024 | IBM ClearQuest (CQ) 9.1 through 9.1.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to... |
| CVE-2024-40641 | HIGH | 7.4 | 0.3% | Jul 17, 2024 | Nuclei is a fast and customizable vulnerability scanner based on simple YAML based DSL. In affected versions it a way t... |
| CVE-2024-40640 | LOW | 2.9 | 0.2% | Jul 17, 2024 | vodozemac is an open source implementation of Olm and Megolm in pure Rust. Versions before 0.7.0 of vodozemac use a non... |
| CVE-2024-40639 | — | — | — | Jul 17, 2024 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2024-40636 | MEDIUM | 5.3 | 0.4% | Jul 17, 2024 | Steeltoe is an open source project that provides a collection of libraries that helps users build production-grade cloud... |
| CVE-2024-40633 | MEDIUM | 5.3 | 0.4% | Jul 17, 2024 | Sylius is an Open Source eCommerce Framework on Symfony. A security vulnerability was discovered in the `/api/v2/shop/ad... |
| CVE-2024-38447 | HIGH | 8.1 | 0.4% | Jul 17, 2024 | NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request for a private draft rep... |
| CVE-2024-38870 | LOW | 3.5 | 0.3% | Jul 17, 2024 | Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104, ... |
| CVE-2024-38446 | MEDIUM | 6.5 | 0.3% | Jul 17, 2024 | NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the restrictions imposed by the... |
| CVE-2024-20435 | HIGH | 7.8 | 0.2% | Jul 17, 2024 | A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to exe... |
| CVE-2024-20429 | HIGH | 7.2 | 0.6% | Jul 17, 2024 | A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authentic... |
| CVE-2024-20419 | CRITICAL | 10 | 80.8% | Jul 17, 2024 | A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauth... |
| CVE-2024-20416 | MEDIUM | 6.5 | 0.9% | Jul 17, 2024 | A vulnerability in the upload module of Cisco RV340 and RV345 Dual WAN Gigabit VPN Routers could allow an authenticated,... |
| CVE-2024-20401 | CRITICAL | 9.8 | 2.3% | Jul 17, 2024 | A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unau... |
| CVE-2024-20400 | MEDIUM | 4.7 | 0.4% | Jul 17, 2024 | A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote ... |
| CVE-2024-20396 | MEDIUM | 6.5 | 0.4% | Jul 17, 2024 | A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain acce... |
| CVE-2024-20395 | HIGH | 7.3 | 0.2% | Jul 17, 2024 | A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacke... |
| CVE-2024-20323 | HIGH | 7.5 | 0.2% | Jul 17, 2024 | A vulnerability in Cisco Intelligent Node (iNode) Software could allow an unauthenticated, remote attacker to hijack the... |
| CVE-2024-20296 | HIGH | 7.2 | 0.5% | Jul 17, 2024 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2024-6830 | HIGH | 7.5 | 0.4% | Jul 17, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Inventory Management System 1.0. A... |
| CVE-2024-6834 | CRITICAL | 9 | 0.3% | Jul 17, 2024 | A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Z... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now