2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5746 | HIGH | 7.2 | 0.9% | Jun 20, 2024 | A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the... |
| CVE-2024-37183 | HIGH | 7.5 | 0.2% | Jun 20, 2024 | Plain text credentials and session ID can be captured with a network sniffer. |
| CVE-2024-36071 | MEDIUM | 6.3 | 0.1% | Jun 20, 2024 | Samsung Magician 8.0.0 on Windows allows an admin to escalate privileges by tampering with the directory and DLL files u... |
| CVE-2024-31586 | MEDIUM | 6.1 | 0.5% | Jun 20, 2024 | A Cross Site Scripting (XSS) vulnerability exists in Computer Laboratory Management System version 1.0. This vulnerabili... |
| CVE-2024-30848 | MEDIUM | 6.1 | 0.3% | Jun 20, 2024 | Cross-site scripting (XSS) vulnerability in SilverSky E-mail service version 5.0.3126 allows remote attackers to inject ... |
| CVE-2024-29390 | HIGH | 7.3 | 0.4% | Jun 20, 2024 | Daily Expenses Management System version 1.0, developed by PHP Gurukul, contains a time-based blind SQL injection vulner... |
| CVE-2024-6154 | MEDIUM | 6.7 | 0.3% | Jun 20, 2024 | Parallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allow... |
| CVE-2024-6153 | HIGH | 7.8 | 0.3% | Jun 20, 2024 | Parallels Desktop Updater Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows local... |
| CVE-2024-6147 | HIGH | 7.8 | 0.4% | Jun 20, 2024 | Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers ... |
| CVE-2024-38093 | MEDIUM | 4.3 | 0.5% | Jun 20, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-38082 | MEDIUM | 4.7 | 0.5% | Jun 20, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-37818 | HIGH | 8.6 | 0.6% | Jun 20, 2024 | Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. ... |
| CVE-2024-37897 | MEDIUM | 5.4 | 0.3% | Jun 20, 2024 | SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azur... |
| CVE-2024-37699 | CRITICAL | 9.8 | 0.5% | Jun 20, 2024 | An issue in DataLife Engine v.17.1 and before is vulnerable to SQL Injection in dboption. |
| CVE-2024-37674 | MEDIUM | 5.5 | 0.6% | Jun 20, 2024 | Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field ... |
| CVE-2024-37352 | LOW | 3.4 | 0.3% | Jun 20, 2024 | There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06 that... |
| CVE-2024-37351 | LOW | 3.4 | 0.3% | Jun 20, 2024 | There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Att... |
| CVE-2024-37350 | MEDIUM | 4.7 | 0.3% | Jun 20, 2024 | There is a cross-site scripting vulnerability in the policy management UI of Absolute Secure Access prior to version 13.... |
| CVE-2024-37349 | LOW | 3.4 | 0.3% | Jun 20, 2024 | There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Att... |
| CVE-2024-37626 | HIGH | 8.8 | 1.8% | Jun 20, 2024 | A command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrar... |
| CVE-2024-37348 | LOW | 3.4 | 0.3% | Jun 20, 2024 | There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Att... |
| CVE-2024-37347 | LOW | 3.4 | 0.3% | Jun 20, 2024 | There is a cross-site scripting vulnerability in the pool configuration component of the management UI of Absolute Secur... |
| CVE-2024-37346 | MEDIUM | 4.9 | 0.4% | Jun 20, 2024 | There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13... |
| CVE-2024-37345 | MEDIUM | 5.4 | 0.2% | Jun 20, 2024 | There is a cross-site scripting vulnerability in the Secure Access administrative UI of Absolute Secure Access prior to ... |
| CVE-2024-37344 | LOW | 3.4 | 0.3% | Jun 20, 2024 | There is a cross-site scripting vulnerability in the Policy management UI of Absolute Secure Access prior to version 13.... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now