2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38371 | CRITICAL | 9.8 | 0.6% | Jun 28, 2024 | authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when usin... |
| CVE-2024-37905 | HIGH | 8.8 | 0.8% | Jun 28, 2024 | authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token me... |
| CVE-2024-35155 | MEDIUM | 6.5 | 0.6% | Jun 28, 2024 | IBM MQ Console 9.3 LTS and 9.3 CD could disclose could allow a remote attacker to obtain sensitive information when a de... |
| CVE-2024-31919 | HIGH | 7.5 | 0.5% | Jun 28, 2024 | IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD, in certain configurations, is vulnerable to a denial of service at... |
| CVE-2024-31912 | HIGH | 8.8 | 0.4% | Jun 28, 2024 | IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations du... |
| CVE-2024-6403 | CRITICAL | 9.8 | 1.0% | Jun 28, 2024 | A vulnerability, which was classified as critical, has been found in Tenda A301 15.13.08.12. Affected by this issue is t... |
| CVE-2024-6402 | CRITICAL | 9.8 | 1.0% | Jun 28, 2024 | A vulnerability classified as critical was found in Tenda A301 15.13.08.12. Affected by this vulnerability is the functi... |
| CVE-2024-38522 | MEDIUM | 6.3 | 0.3% | Jun 28, 2024 | Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The CSP policy ap... |
| CVE-2024-38521 | MEDIUM | 6.1 | 0.4% | Jun 28, 2024 | Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. There is a stored... |
| CVE-2024-35139 | MEDIUM | 5.5 | 0.2% | Jun 28, 2024 | IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information fr... |
| CVE-2024-35137 | MEDIUM | 6.2 | 0.3% | Jun 28, 2024 | IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileg... |
| CVE-2024-29039 | HIGH | 8.1 | 1.0% | Jun 28, 2024 | tpm2 is the source repository for the Trusted Platform Module (TPM2.0) tools. This vulnerability allows attackers to man... |
| CVE-2024-38531 | LOW | 3.6 | 0.1% | Jun 28, 2024 | Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A bui... |
| CVE-2024-29038 | LOW | 3.3 | 0.4% | Jun 28, 2024 | tpm2-tools is the source repository for the Trusted Platform Module (TPM2.0) tools. A malicious attacker can generate ar... |
| CVE-2024-3816 | CRITICAL | 9.8 | 0.5% | Jun 28, 2024 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar... |
| CVE-2024-3801 | MEDIUM | 6.1 | 0.3% | Jun 28, 2024 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in one of GET h... |
| CVE-2024-3800 | MEDIUM | 6.1 | 0.3% | Jun 28, 2024 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in requested fi... |
| CVE-2024-39704 | CRITICAL | 9.8 | 1.4% | Jun 28, 2024 | Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev. 1.4.0 allows a remote attacker to ex... |
| CVE-2024-37741 | MEDIUM | 5.4 | 0.3% | Jun 28, 2024 | OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture. |
| CVE-2024-5737 | MEDIUM | 6.1 | 1.1% | Jun 28, 2024 | Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/ht... |
| CVE-2024-5736 | HIGH | 7.5 | 1.2% | Jun 28, 2024 | Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to a... |
| CVE-2024-5735 | HIGH | 7.5 | 1.5% | Jun 28, 2024 | Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised atta... |
| CVE-2024-5925 | MEDIUM | 6.4 | 0.3% | Jun 28, 2024 | The Theron Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the them... |
| CVE-2024-5922 | MEDIUM | 6.4 | 0.3% | Jun 28, 2024 | The Scylla lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the them... |
| CVE-2024-5662 | MEDIUM | 6.4 | 0.4% | Jun 28, 2024 | The Ultimate Post Kit Addons For Elementor – (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline,... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now