2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39220 | MEDIUM | 6.5 | 0.4% | Jul 3, 2024 | BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD, AV-02FDE, A... |
| CVE-2024-6471 | HIGH | 8.8 | 0.6% | Jul 3, 2024 | A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management 1.0. This affe... |
| CVE-2024-37726 | MEDIUM | 6.8 | 0.9% | Jul 3, 2024 | Insecure Permissions vulnerability in Micro-Star International Co., Ltd MSI Center v.2.0.36.0 allows a local attacker to... |
| CVE-2024-32937 | CRITICAL | 9.8 | 26.3% | Jul 3, 2024 | An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.... |
| CVE-2024-6470 | LOW | 2.7 | 0.4% | Jul 3, 2024 | A vulnerability was found in playSMS 1.4.3. It has been rated as problematic. Affected by this issue is some unknown fun... |
| CVE-2024-5672 | HIGH | 7.2 | 1.2% | Jul 3, 2024 | A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization ... |
| CVE-2024-6427 | HIGH | 7.5 | 0.6% | Jul 3, 2024 | Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can u... |
| CVE-2024-6426 | HIGH | 7.1 | 0.3% | Jul 3, 2024 | Information exposure vulnerability in MESbook 20221021.03 version, the exploitation of which could allow a local attacke... |
| CVE-2024-6469 | HIGH | 8.8 | 0.7% | Jul 3, 2024 | A vulnerability was found in playSMS 1.4.3. It has been declared as problematic. Affected by this vulnerability is an un... |
| CVE-2024-6428 | MEDIUM | 6.5 | 0.4% | Jul 3, 2024 | Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2, 9.5.x <= 9.5.5 fail to prevent specifying a RemoteId when cre... |
| CVE-2024-39830 | MEDIUM | 5.9 | 0.4% | Jul 3, 2024 | Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled,... |
| CVE-2024-39807 | MEDIUM | 5.3 | 0.3% | Jul 3, 2024 | Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an... |
| CVE-2024-39361 | MEDIUM | 5.4 | 0.3% | Jul 3, 2024 | Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a Rem... |
| CVE-2024-39353 | LOW | 2.7 | 0.3% | Jul 3, 2024 | Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them ... |
| CVE-2024-36257 | MEDIUM | 5.3 | 0.3% | Jul 3, 2024 | Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to... |
| CVE-2024-6340 | MEDIUM | 5.4 | 0.4% | Jul 3, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Coun... |
| CVE-2024-6263 | MEDIUM | 5.4 | 0.3% | Jul 3, 2024 | The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all ver... |
| CVE-2024-4482 | MEDIUM | 5.4 | 0.4% | Jul 3, 2024 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre... |
| CVE-2024-38453 | HIGH | 7.5 | 0.4% | Jul 3, 2024 | The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current vers... |
| CVE-2024-37082 | CRITICAL | 9.1 | 0.5% | Jul 3, 2024 | When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be po... |
| CVE-2024-2376 | HIGH | 8.8 | 0.4% | Jul 3, 2024 | The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to ... |
| CVE-2024-2375 | MEDIUM | 5.4 | 0.3% | Jul 3, 2024 | The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could all... |
| CVE-2024-2235 | MEDIUM | 4.3 | 0.2% | Jul 3, 2024 | The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make use... |
| CVE-2024-2234 | MEDIUM | 5.4 | 0.3% | Jul 3, 2024 | The Himer WordPress theme before 2.1.1 does not sanitise and escape some of its Post settings, which could allow high pr... |
| CVE-2024-2233 | MEDIUM | 4.3 | 0.2% | Jul 3, 2024 | The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make log... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now