2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39473 | MEDIUM | 5.5 | 0.2% | Jul 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Fix input format query of... |
| CVE-2024-39472 | MEDIUM | 5.5 | 0.2% | Jul 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: xfs: fix log recovery buffer allocation for the leg... |
| CVE-2024-36041 | HIGH | 7.8 | 0.3% | Jul 5, 2024 | KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ... |
| CVE-2024-34481 | MEDIUM | 6.1 | 0.6% | Jul 5, 2024 | drupal-wiki.com Drupal Wiki before 8.31.1 allows XSS via comments, captions, and image titles of a Wiki page. |
| CVE-2024-32498 | MEDIUM | 6.5 | 0.8% | Jul 5, 2024 | An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file... |
| CVE-2024-39943 | HIGH | 8.8 | 48.8% | Jul 4, 2024 | rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote auth... |
| CVE-2024-39937 | HIGH | 7.5 | 0.9% | Jul 4, 2024 | supOS 5.0 allows api/image/download?fileName=../ directory traversal for reading files. |
| CVE-2024-39936 | MEDIUM | 5.9 | 0.5% | Jul 4, 2024 | An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x th... |
| CVE-2024-39935 | HIGH | 8.8 | 0.9% | Jul 4, 2024 | jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated u... |
| CVE-2024-6511 | MEDIUM | 6.1 | 0.3% | Jul 4, 2024 | A vulnerability classified as problematic was found in y_project RuoYi up to 4.7.9. Affected by this vulnerability is th... |
| CVE-2024-39934 | HIGH | 7.8 | 0.2% | Jul 4, 2024 | Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup ... |
| CVE-2024-37474 | MEDIUM | 5.4 | 0.3% | Jul 4, 2024 | Cross Site Scripting (XSS) vulnerability in Automattic Newspack Ads allows Stored XSS.This issue affects Newspack Ads: f... |
| CVE-2024-37472 | MEDIUM | 6.1 | 0.3% | Jul 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice ... |
| CVE-2024-37471 | MEDIUM | 6.1 | 0.3% | Jul 4, 2024 | Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core:... |
| CVE-2024-37476 | MEDIUM | 5.4 | 0.3% | Jul 4, 2024 | Cross Site Scripting (XSS) vulnerability in Automattic Newspack Campaigns allows Stored XSS.This issue affects Newspack ... |
| CVE-2024-6513 | — | — | — | Jul 4, 2024 | Rejected reason: CVE assigned by mistake as a duplicate. |
| CVE-2024-39933 | HIGH | 7.7 | 0.7% | Jul 4, 2024 | Gogs through 0.13.0 allows argument injection during the tagging of a new release. |
| CVE-2024-39932 | CRITICAL | 9.9 | 17.2% | Jul 4, 2024 | Gogs through 0.13.0 allows argument injection during the previewing of changes. |
| CVE-2024-39931 | CRITICAL | 9.9 | 50.7% | Jul 4, 2024 | Gogs through 0.13.0 allows deletion of internal files. |
| CVE-2024-39930 | CRITICAL | 9.9 | 7.3% | Jul 4, 2024 | The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code ... |
| CVE-2024-39929 | MEDIUM | 5.4 | 41.2% | Jul 4, 2024 | Exim through 4.97.1 misparses a multiline RFC 2231 header filename, and thus remote attackers can bypass a $mime_filenam... |
| CVE-2024-22277 | MEDIUM | 5.4 | 0.3% | Jul 4, 2024 | VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to ... |
| CVE-2024-6506 | HIGH | 8.2 | 0.5% | Jul 4, 2024 | Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This ... |
| CVE-2024-39211 | MEDIUM | 5.3 | 1.1% | Jul 4, 2024 | Kaiten 57.128.8 allows remote attackers to enumerate user accounts via a crafted POST request, because a login response ... |
| CVE-2024-39165 | CRITICAL | 9.8 | 0.8% | Jul 4, 2024 | QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary cod... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now