2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39021 | MEDIUM | 5.4 | 0.2% | Jul 5, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApiData_deal.php?... |
| CVE-2024-39020 | MEDIUM | 6.3 | 0.2% | Jul 5, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/vpsApiData_deal.php?... |
| CVE-2024-39019 | MEDIUM | 5.4 | 0.2% | Jul 5, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/idcProData_deal.php?... |
| CVE-2024-34361 | HIGH | 8.8 | 2.8% | Jul 5, 2024 | Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vul... |
| CVE-2024-39687 | HIGH | 7.2 | 0.6% | Jul 5, 2024 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards. At present... |
| CVE-2024-39321 | HIGH | 7.5 | 0.6% | Jul 5, 2024 | Traefik is an HTTP reverse proxy and load balancer. Versions prior to 2.11.6, 3.0.4, and 3.1.0-rc3 have a vulnerability ... |
| CVE-2024-39174 | MEDIUM | 6.1 | 0.3% | Jul 5, 2024 | A cross-site scripting (XSS) vulnerability in the Publish Article function of yzmcms v7.1 allows attackers to execute ar... |
| CVE-2024-37903 | HIGH | 8.2 | 0.5% | Jul 5, 2024 | Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and ... |
| CVE-2024-39178 | MEDIUM | 5.4 | 0.4% | Jul 5, 2024 | MyPower vc8100 V100R001C00B030 was discovered to contain an arbitrary file read vulnerability via the component /tcpdump... |
| CVE-2024-39150 | MEDIUM | 5.9 | 0.3% | Jul 5, 2024 | vditor v.3.9.8 and before is vulnerable to Arbitrary file read via a crafted data packet. |
| CVE-2024-37767 | HIGH | 7.5 | 0.4% | Jul 5, 2024 | Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information v... |
| CVE-2024-27717 | MEDIUM | 6.5 | 0.2% | Jul 5, 2024 | Cross Site Request Forgery vulnerability in Eskooly Free Online School Management Software v.3.0 and before allows a rem... |
| CVE-2024-27716 | MEDIUM | 5.4 | 0.4% | Jul 5, 2024 | Cross Site Scripting vulnerability in Eskooly Web Product v.3.0 and before allows a remote attacker to execute arbitrary... |
| CVE-2024-27715 | HIGH | 8.2 | 0.4% | Jul 5, 2024 | An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile... |
| CVE-2024-27713 | HIGH | 8.8 | 0.6% | Jul 5, 2024 | An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile... |
| CVE-2024-27712 | CRITICAL | 9.8 | 0.6% | Jul 5, 2024 | An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile... |
| CVE-2024-27711 | HIGH | 8.8 | 0.4% | Jul 5, 2024 | An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile... |
| CVE-2024-27710 | CRITICAL | 9.8 | 0.6% | Jul 5, 2024 | An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile... |
| CVE-2024-27709 | CRITICAL | 9.8 | 0.6% | Jul 5, 2024 | SQL Injection vulnerability in Eskooly Web Product v.3.0 allows a remote attacker to execute arbitrary code via the sear... |
| CVE-2024-39210 | HIGH | 7.5 | 0.8% | Jul 5, 2024 | Best House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page par... |
| CVE-2024-37769 | HIGH | 8.8 | 0.5% | Jul 5, 2024 | Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a cra... |
| CVE-2024-37768 | CRITICAL | 9.1 | 0.6% | Jul 5, 2024 | 14Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id. |
| CVE-2024-29319 | CRITICAL | 9.8 | 0.4% | Jul 5, 2024 | Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. ... |
| CVE-2024-29318 | MEDIUM | 5.4 | 0.3% | Jul 5, 2024 | Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file wi... |
| CVE-2024-23998 | CRITICAL | 9.6 | 0.7% | Jul 5, 2024 | goanother Another Redis Desktop Manager =<1.6.1 is vulnerable to Cross Site Scripting (XSS) via src/components/Setting.v... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now