2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39243 | CRITICAL | 9.8 | 0.5% | Jun 26, 2024 | An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/adm... |
| CVE-2024-39242 | MEDIUM | 6.1 | 0.3% | Jun 26, 2024 | A cross-site scripting (XSS) vulnerability in skycaiji v2.8 allows attackers to execute arbitrary web scripts or HTML vi... |
| CVE-2024-39241 | MEDIUM | 6.1 | 0.3% | Jun 26, 2024 | Cross Site Scripting (XSS) vulnerability in skycaiji 2.8 allows attackers to run arbitrary code via /admin/tool/preview. |
| CVE-2024-38950 | MEDIUM | 6.5 | 0.4% | Jun 26, 2024 | Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to ... |
| CVE-2024-38949 | MEDIUM | 6.5 | 0.4% | Jun 26, 2024 | Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to ... |
| CVE-2024-38527 | MEDIUM | 5.4 | 0.4% | Jun 26, 2024 | ZenUML is JavaScript-based diagramming tool that requires no server, using Markdown-inspired text definitions and a rend... |
| CVE-2024-38520 | MEDIUM | 5.3 | 0.5% | Jun 26, 2024 | SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. When SoftEtherVPN is deployed with L2TP enab... |
| CVE-2024-38375 | MEDIUM | 5.3 | 0.3% | Jun 26, 2024 | @fastly/js-compute is a JavaScript SDK and runtime for building Fastly Compute applications. The implementation of sever... |
| CVE-2024-33329 | HIGH | 7.5 | 0.7% | Jun 26, 2024 | A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass authentication and access interna... |
| CVE-2024-33328 | MEDIUM | 6.1 | 0.4% | Jun 26, 2024 | A cross-site scripting (XSS) vulnerability in the component main.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to e... |
| CVE-2024-33327 | MEDIUM | 6.1 | 0.4% | Jun 26, 2024 | A cross-site scripting (XSS) vulnerability in the component UrlAccessibilityEvaluation.jsp of Lumisxp v15.0.x to v16.1.x... |
| CVE-2024-33326 | MEDIUM | 6.1 | 0.8% | Jun 26, 2024 | A cross-site scripting (XSS) vulnerability in the component XsltResultControllerHtml.jsp of Lumisxp v15.0.x to v16.1.x a... |
| CVE-2024-35545 | MEDIUM | 6.1 | 0.4% | Jun 26, 2024 | MAP-OS v4.45.0 and earlier was discovered to contain a cross-site scripting (XSS) vulnerability. |
| CVE-2024-6354 | HIGH | 7.2 | 0.8% | Jun 26, 2024 | Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows a... |
| CVE-2024-39460 | MEDIUM | 4.3 | 0.5% | Jun 26, 2024 | Jenkins Bitbucket Branch Source Plugin 886.v44cf5e4ecec5 and earlier prints the Bitbucket OAuth access token as part of ... |
| CVE-2024-39459 | MEDIUM | 4.3 | 0.4% | Jun 26, 2024 | In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypt... |
| CVE-2024-39458 | LOW | 3.1 | 0.4% | Jun 26, 2024 | When Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message c... |
| CVE-2024-38272 | MEDIUM | 4.3 | 0.2% | Jun 26, 2024 | There exists a vulnerability in Quick Share/Nearby, where an attacker can bypass the accept file dialog on Quick Share W... |
| CVE-2024-38271 | MEDIUM | 4.8 | 0.2% | Jun 26, 2024 | There exists a vulnerability in Quick Share/Nearby, where an attacker can force a victim to stay connected to a temporar... |
| CVE-2024-25637 | MEDIUM | 5.4 | 0.3% | Jun 26, 2024 | October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not ... |
| CVE-2024-6349 | — | — | — | Jun 26, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-4604 | MEDIUM | 6.1 | 0.2% | Jun 26, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Ma... |
| CVE-2024-4228 | CRITICAL | 9.8 | 0.5% | Jun 26, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive ... |
| CVE-2024-6344 | LOW | 2.4 | 0.4% | Jun 26, 2024 | A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an ... |
| CVE-2024-37252 | CRITICAL | 9.3 | 0.5% | Jun 26, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subs... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now