2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2231 | MEDIUM | 6.5 | 0.4% | Jul 3, 2024 | The allows any authenticated user to join a private group due to a missing authorization check on a function |
| CVE-2024-2040 | MEDIUM | 4.3 | 0.2% | Jul 3, 2024 | The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make use... |
| CVE-2024-4543 | MEDIUM | 4.3 | 0.2% | Jul 3, 2024 | The Snippet Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-39920 | MEDIUM | 4.3 | 0.6% | Jul 3, 2024 | The TCP protocol in RFC 9293 has a timing side channel that makes it easier for remote attackers to infer the content of... |
| CVE-2024-32673 | MEDIUM | 6.7 | 0.2% | Jul 3, 2024 | Improper Validation of Array Index vulnerability in Samsung Open Source Walrus Webassembly runtime engine allows a segme... |
| CVE-2024-4708 | CRITICAL | 9.8 | 1.0% | Jul 2, 2024 | mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device... |
| CVE-2024-6453 | HIGH | 8.8 | 0.6% | Jul 2, 2024 | A vulnerability was found in itsourcecode Farm Management System 1.0. It has been declared as critical. Affected by this... |
| CVE-2024-24791 | HIGH | 7.5 | 1.4% | Jul 2, 2024 | The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" hea... |
| CVE-2024-39326 | MEDIUM | 4.4 | 0.3% | Jul 2, 2024 | SkillTree is a micro-learning gamification platform. Prior to version 2.12.6, the endpoint `/admin/projects/{projectnam... |
| CVE-2024-39325 | MEDIUM | 5.3 | 0.4% | Jul 2, 2024 | aimeos/ai-controller-frontend is the Aimeos frontend controller. Prior to versions 2024.04.2, 2023.10.9, 2022.10.8, 202... |
| CVE-2024-39324 | LOW | 3.8 | 0.4% | Jul 2, 2024 | aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2... |
| CVE-2024-39322 | MEDIUM | 5.5 | 0.5% | Jul 2, 2024 | aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 202... |
| CVE-2024-6452 | HIGH | 8.8 | 0.5% | Jul 2, 2024 | A vulnerability classified as critical was found in linlinjava litemall up to 1.8.0. Affected by this vulnerability is a... |
| CVE-2024-39315 | MEDIUM | 6.5 | 0.4% | Jul 2, 2024 | Pomerium is an identity and context-aware access proxy. Prior to version 0.26.1, the Pomerium user info page (at `/.pome... |
| CVE-2024-38537 | CRITICAL | 9.8 | 1.4% | Jul 2, 2024 | Fides is an open-source privacy engineering platform. `fides.js`, a client-side script used to interact with the consent... |
| CVE-2024-6382 | HIGH | 7.5 | 0.3% | Jul 2, 2024 | Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. T... |
| CVE-2024-6381 | MEDIUM | 5.3 | 0.4% | Jul 2, 2024 | The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function ... |
| CVE-2024-6341 | — | — | — | Jul 2, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2024-39894 | HIGH | 7.5 | 1.6% | Jul 2, 2024 | OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sud... |
| CVE-2024-39891 | MEDIUM | 5.3 | 1.5% | Jul 2, 2024 | In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoin... |
| CVE-2024-39206 | HIGH | 7.5 | 0.5% | Jul 2, 2024 | An issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials ... |
| CVE-2024-5866 | MEDIUM | 4.3 | 0.4% | Jul 2, 2024 | Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulner... |
| CVE-2024-5865 | MEDIUM | 6.5 | 0.5% | Jul 2, 2024 | Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulner... |
| CVE-2024-4467 | HIGH | 7.8 | 0.3% | Jul 2, 2024 | A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `... |
| CVE-2024-3826 | HIGH | 8.6 | 0.3% | Jul 2, 2024 | In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now