2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39310 | MEDIUM | 5.4 | 0.3% | Jul 1, 2024 | The Basil recipe theme for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `post_title` paramet... |
| CVE-2024-39309 | CRITICAL | 9.8 | 20.2% | Jul 1, 2024 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability ... |
| CVE-2024-37765 | HIGH | 8.8 | 0.8% | Jul 1, 2024 | Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page. |
| CVE-2024-37764 | MEDIUM | 5.4 | 0.6% | Jul 1, 2024 | MachForm up to version 19 is affected by an authenticated stored cross-site scripting. |
| CVE-2024-37763 | MEDIUM | 5.4 | 0.7% | Jul 1, 2024 | MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid s... |
| CVE-2024-37762 | CRITICAL | 9.9 | 1.5% | Jul 1, 2024 | MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code executio... |
| CVE-2024-23737 | MEDIUM | 5.4 | 0.1% | Jul 1, 2024 | Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows a... |
| CVE-2024-23736 | HIGH | 8.8 | 0.1% | Jul 1, 2024 | Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to ma... |
| CVE-2024-5322 | CRITICAL | 9.1 | 0.4% | Jul 1, 2024 | The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can l... |
| CVE-2024-39305 | CRITICAL | 9.1 | 0.6% | Jul 1, 2024 | Envoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy... |
| CVE-2024-38368 | CRITICAL | 9.3 | 14.7% | Jul 1, 2024 | trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older p... |
| CVE-2024-38367 | CRITICAL | 9.6 | 11.0% | Jul 1, 2024 | trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. Prior to commit d4fa66f49cedab44... |
| CVE-2024-38366 | CRITICAL | 10 | 17.6% | Jul 1, 2024 | trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies... |
| CVE-2024-32230 | HIGH | 7.8 | 0.4% | Jul 1, 2024 | FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in... |
| CVE-2024-32229 | HIGH | 8.4 | 0.3% | Jul 1, 2024 | FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column. |
| CVE-2024-32228 | MEDIUM | 6.6 | 0.2% | Jul 1, 2024 | FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end. |
| CVE-2024-28200 | CRITICAL | 9.8 | 1.9% | Jul 1, 2024 | The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in a... |
| CVE-2024-39249 | HIGH | 7.5 | 0.8% | Jul 1, 2024 | Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in aut... |
| CVE-2024-39573 | HIGH | 7.5 | 35.4% | Jul 1, 2024 | Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules t... |
| CVE-2024-39303 | MEDIUM | 5.4 | 0.3% | Jul 1, 2024 | Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when resto... |
| CVE-2024-39251 | CRITICAL | 10 | 0.7% | Jul 1, 2024 | An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers... |
| CVE-2024-39236 | CRITICAL | 9.8 | 0.9% | Jul 1, 2024 | Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. Thi... |
| CVE-2024-38513 | CRITICAL | 9.8 | 0.7% | Jul 1, 2024 | Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a sessio... |
| CVE-2024-38477 | HIGH | 7.5 | 3.2% | Jul 1, 2024 | null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server vi... |
| CVE-2024-38476 | CRITICAL | 9.8 | 41.6% | Jul 1, 2024 | Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local s... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now