2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-40598 | MEDIUM | 4.3 | 0.3% | Jul 7, 2024 | An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The API can expose suppressed informati... |
| CVE-2024-40597 | HIGH | 7.5 | 0.4% | Jul 7, 2024 | An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose suppressed information fo... |
| CVE-2024-40596 | MEDIUM | 4.3 | 0.3% | Jul 7, 2024 | An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. The Special:Investigate feature can exp... |
| CVE-2024-6095 | MEDIUM | 5.8 | 2.5% | Jul 6, 2024 | A vulnerability in the /models/apply endpoint of mudler/localai versions 2.15.0 allows for Server-Side Request Forgery (... |
| CVE-2024-37554 | MEDIUM | 5.4 | 0.2% | Jul 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam Ultra... |
| CVE-2024-37553 | MEDIUM | 5.4 | 0.3% | Jul 6, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Axelerant T... |
| CVE-2024-37547 | MEDIUM | 6.5 | 0.5% | Jul 6, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Livemesh Livemesh Addons... |
| CVE-2024-37546 | MEDIUM | 5.4 | 0.2% | Jul 6, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in biplob018 I... |
| CVE-2024-37542 | MEDIUM | 6.3 | 0.2% | Jul 6, 2024 | Missing Authorization vulnerability in WpDevArt Responsive Image Gallery, Gallery Album.This issue affects Responsive Im... |
| CVE-2024-37541 | MEDIUM | 5.4 | 0.2% | Jul 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StaxWP Elementor A... |
| CVE-2024-37539 | MEDIUM | 5.4 | 0.3% | Jul 6, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Delower WP ... |
| CVE-2024-39486 | HIGH | 7 | 0.2% | Jul 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/drm_file: Fix pid refcounting race <maarten.la... |
| CVE-2024-37260 | CRITICAL | 9.3 | 0.3% | Jul 6, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Theme-Ruby Foxiz.This issue affects Foxiz: from n/a through 2.3.5. |
| CVE-2024-37234 | LOW | 3.5 | 0.3% | Jul 6, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kodezen Limited Academy LMS.This issue affects Acad... |
| CVE-2024-37208 | MEDIUM | 4.9 | 0.2% | Jul 6, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Robert Macchi WP Scraper.This issue affects WP Scraper: from n/a thr... |
| CVE-2024-5616 | MEDIUM | 4.3 | 0.2% | Jul 6, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability exists in mudler/LocalAI versions up to and including 2.15.0, which al... |
| CVE-2024-40594 | LOW | 2.3 | 0.1% | Jul 6, 2024 | The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a l... |
| CVE-2024-39182 | HIGH | 7.5 | 0.4% | Jul 5, 2024 | An information disclosure vulnerability in ISPmanager v6.98.0 allows attackers to access sensitive details of the root u... |
| CVE-2024-33862 | HIGH | 7.5 | 0.6% | Jul 5, 2024 | A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.05.374.54 could allow... |
| CVE-2024-5753 | HIGH | 7.5 | 0.6% | Jul 5, 2024 | vanna-ai/vanna version v0.3.4 is vulnerable to SQL injection in some file-critical functions such as `pg_read_file()`. T... |
| CVE-2024-39696 | HIGH | 8.1 | 0.5% | Jul 5, 2024 | Evmos is a decentralized Ethereum Virtual Machine chain on the Cosmos Network. Prior to version 19.0.0, a user can creat... |
| CVE-2024-39691 | MEDIUM | 4.3 | 0.5% | Jul 5, 2024 | matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The fix for GHSA-wm4w-7h2q-3pf7 / CVE-2... |
| CVE-2024-39689 | HIGH | 7.5 | 1.0% | Jul 5, 2024 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verify... |
| CVE-2024-39023 | HIGH | 8.8 | 0.3% | Jul 5, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/info_deal.php?mudi=ad... |
| CVE-2024-39022 | HIGH | 8.8 | 0.3% | Jul 5, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/infoSys_deal.php?mud... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now