2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7569 | CRITICAL | 9.8 | 1.6% | Aug 13, 2024 | An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows a... |
| CVE-2024-38199 | CRITICAL | 9.8 | 2.2% | Aug 13, 2024 | Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability |
| CVE-2024-38160 | CRITICAL | 9.1 | 2.2% | Aug 13, 2024 | Windows Network Virtualization Remote Code Execution Vulnerability |
| CVE-2024-38159 | CRITICAL | 9.1 | 2.2% | Aug 13, 2024 | Windows Network Virtualization Remote Code Execution Vulnerability |
| CVE-2024-38140 | CRITICAL | 9.8 | 3.8% | Aug 13, 2024 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability |
| CVE-2024-38108 | CRITICAL | 9.3 | 1.1% | Aug 13, 2024 | Azure Stack Hub Spoofing Vulnerability |
| CVE-2024-38063 | CRITICAL | 9.8 | 70.6% | Aug 13, 2024 | Windows TCP/IP Remote Code Execution Vulnerability |
| CVE-2024-7746 | CRITICAL | 9.8 | 0.5% | Aug 13, 2024 | Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Auth... |
| CVE-2024-6788 | CRITICAL | 9.8 | 0.5% | Aug 13, 2024 | A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the pa... |
| CVE-2024-41623 | CRITICAL | 9.8 | 0.7% | Aug 13, 2024 | An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code ... |
| CVE-2024-43160 | CRITICAL | 10 | 4.6% | Aug 13, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP:... |
| CVE-2024-43153 | CRITICAL | 9.8 | 0.6% | Aug 13, 2024 | Incorrect Privilege Assignment vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <... |
| CVE-2024-43141 | CRITICAL | 9.8 | 0.6% | Aug 13, 2024 | Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Inj... |
| CVE-2024-39651 | CRITICAL | 9.3 | 0.5% | Aug 13, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPWeb WooCommerce PDF Vo... |
| CVE-2024-41940 | CRITICAL | 9.1 | 0.6% | Aug 13, 2024 | A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly valid... |
| CVE-2024-41730 | CRITICAL | 9.8 | 75.6% | Aug 13, 2024 | In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an u... |
| CVE-2024-33003 | CRITICAL | 9.1 | 0.5% | Aug 13, 2024 | Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, e... |
| CVE-2024-7094 | CRITICAL | 9.8 | 37.5% | Aug 13, 2024 | The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection lead... |
| CVE-2024-7707 | CRITICAL | 9.8 | 1.3% | Aug 13, 2024 | A vulnerability was found in Tenda FH1206 02.03.01.35 and classified as critical. Affected by this issue is the function... |
| CVE-2024-43360 | CRITICAL | 9.8 | 6.2% | Aug 12, 2024 | ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based... |
| CVE-2024-42547 | CRITICAL | 9.8 | 0.6% | Aug 12, 2024 | TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the http_host parameter in the loginauth ... |
| CVE-2024-42546 | CRITICAL | 9.8 | 0.6% | Aug 12, 2024 | TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the password parameter in the loginauth f... |
| CVE-2024-42545 | CRITICAL | 9.8 | 0.7% | Aug 12, 2024 | TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg functio... |
| CVE-2024-42543 | CRITICAL | 9.8 | 0.7% | Aug 12, 2024 | TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth f... |
| CVE-2024-42480 | CRITICAL | 9.9 | 0.6% | Aug 12, 2024 | Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the to... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now