2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38475 | CRITICAL | 9.1 | 100.0% | Jul 1, 2024 | Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to fi... |
| CVE-2024-38474 | CRITICAL | 9.8 | 2.5% | Jul 1, 2024 | Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts i... |
| CVE-2024-38473 | HIGH | 8.1 | 25.9% | Jul 1, 2024 | Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be... |
| CVE-2024-38472 | HIGH | 7.5 | 68.0% | Jul 1, 2024 | SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and maliciou... |
| CVE-2024-37298 | HIGH | 7.5 | 1.1% | Jul 1, 2024 | gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a s... |
| CVE-2024-37146 | MEDIUM | 6.1 | 0.4% | Jul 1, 2024 | Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a ... |
| CVE-2024-37145 | MEDIUM | 6.1 | 0.5% | Jul 1, 2024 | Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a ... |
| CVE-2024-36423 | MEDIUM | 6.1 | 0.4% | Jul 1, 2024 | Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a ... |
| CVE-2024-36387 | MEDIUM | 5.4 | 1.7% | Jul 1, 2024 | Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a cr... |
| CVE-2024-39879 | MEDIUM | 5.3 | 0.3% | Jul 1, 2024 | In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings |
| CVE-2024-39878 | MEDIUM | 5.3 | 0.3% | Jul 1, 2024 | In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection |
| CVE-2024-36997 | HIGH | 8.1 | 0.5% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin... |
| CVE-2024-36996 | MEDIUM | 5.3 | 0.4% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an a... |
| CVE-2024-36995 | LOW | 3.5 | 0.2% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9... |
| CVE-2024-36994 | MEDIUM | 5.4 | 0.3% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9... |
| CVE-2024-36993 | MEDIUM | 5.4 | 0.4% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9... |
| CVE-2024-36992 | MEDIUM | 5.4 | 0.3% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9... |
| CVE-2024-36991 | HIGH | 7.5 | 13.1% | Jul 1, 2024 | In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on t... |
| CVE-2024-36990 | MEDIUM | 6.5 | 0.7% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an a... |
| CVE-2024-36989 | MEDIUM | 4.3 | 0.3% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a lo... |
| CVE-2024-36987 | MEDIUM | 6.5 | 0.3% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an a... |
| CVE-2024-36986 | MEDIUM | 5.7 | 0.4% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9... |
| CVE-2024-36985 | HIGH | 8.8 | 6.5% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or powe... |
| CVE-2024-36984 | HIGH | 8.8 | 1.4% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially... |
| CVE-2024-36983 | HIGH | 8.8 | 1.0% | Jul 1, 2024 | In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now