2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24554 | HIGH | 8.2 | 0.2% | Jun 24, 2024 | Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the A... |
| CVE-2024-4460 | — | — | — | Jun 24, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-24553 | HIGH | 7.5 | 0.2% | Jun 24, 2024 | Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords ... |
| CVE-2024-24552 | HIGH | 8.8 | 0.4% | Jun 24, 2024 | A session fixation vulnerability in Bludit allows an attacker to bypass the server's authentication if they can trick an... |
| CVE-2024-24551 | HIGH | 8.8 | 0.8% | Jun 24, 2024 | A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code throu... |
| CVE-2024-24550 | HIGH | 8.1 | 0.7% | Jun 24, 2024 | A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arb... |
| CVE-2024-4900 | MEDIUM | 6.1 | 0.3% | Jun 24, 2024 | The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contr... |
| CVE-2024-4899 | MEDIUM | 5 | 0.3% | Jun 24, 2024 | The SEOPress WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high... |
| CVE-2024-6280 | CRITICAL | 9.8 | 0.7% | Jun 24, 2024 | A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. This a... |
| CVE-2024-6279 | HIGH | 8.8 | 0.5% | Jun 24, 2024 | A vulnerability was found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as critical. Affected by... |
| CVE-2024-6278 | HIGH | 8.8 | 0.6% | Jun 24, 2024 | A vulnerability has been found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as critical. Affect... |
| CVE-2024-6277 | HIGH | 8.8 | 0.6% | Jun 24, 2024 | A vulnerability, which was classified as critical, was found in lahirudanushka School Management System 1.0.0/1.0.1. Aff... |
| CVE-2024-4499 | MEDIUM | 6.3 | 0.2% | Jun 24, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax ... |
| CVE-2024-6276 | HIGH | 8.8 | 0.6% | Jun 24, 2024 | A vulnerability, which was classified as critical, has been found in lahirudanushka School Management System 1.0.0/1.0.1... |
| CVE-2024-6275 | HIGH | 8.8 | 0.6% | Jun 24, 2024 | A vulnerability classified as critical was found in lahirudanushka School Management System 1.0.0/1.0.1. This vulnerabil... |
| CVE-2024-6274 | HIGH | 8.8 | 0.5% | Jun 24, 2024 | A vulnerability classified as critical has been found in lahirudanushka School Management System 1.0.0/1.0.1. This affec... |
| CVE-2024-3121 | LOW | 3.3 | 0.4% | Jun 24, 2024 | A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version... |
| CVE-2024-39337 | MEDIUM | 6.5 | 0.3% | Jun 24, 2024 | Click Studios Passwordstate Core before 9.8 build 9858 allows Authentication Bypass. |
| CVE-2024-39334 | MEDIUM | 6.5 | 0.4% | Jun 23, 2024 | MENDELSON AS4 before 2024 B376 has a client-side vulnerability when a trading partner provides prepared XML data. When a... |
| CVE-2024-6273 | MEDIUM | 6.1 | 0.6% | Jun 23, 2024 | A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as problematic. Affected by ... |
| CVE-2024-39331 | CRITICAL | 9.8 | 1.3% | Jun 23, 2024 | In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe... |
| CVE-2024-4841 | LOW | 3.3 | 0.7% | Jun 23, 2024 | A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode... |
| CVE-2024-6269 | HIGH | 7.2 | 20.6% | Jun 23, 2024 | A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical. This vulnerability affects the function ... |
| CVE-2024-6268 | CRITICAL | 9.8 | 0.6% | Jun 23, 2024 | A vulnerability, which was classified as critical, has been found in lahirudanushka School Management System 1.0.0/1.0.1... |
| CVE-2024-6267 | MEDIUM | 4.8 | 0.5% | Jun 23, 2024 | A vulnerability classified as problematic was found in SourceCodester Service Provider Management System 1.0. Affected b... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now