2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36289 | MEDIUM | 5.3 | 0.2% | Jun 17, 2024 | Reusing a nonce, key pair in encryption issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for An... |
| CVE-2024-36279 | MEDIUM | 5.3 | 0.1% | Jun 17, 2024 | Reliance on obfuscation or encryption of security-relevant inputs without integrity checking issue exists in "FreeFrom -... |
| CVE-2024-36277 | MEDIUM | 5.3 | 0.3% | Jun 17, 2024 | Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3... |
| CVE-2024-5650 | HIGH | 8.5 | 0.3% | Jun 17, 2024 | DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an at... |
| CVE-2024-6047 | CRITICAL | 9.8 | 10.0% | Jun 17, 2024 | Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote ... |
| CVE-2024-4305 | MEDIUM | 6.8 | 0.4% | Jun 17, 2024 | The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.1.0 does not validate and escape som... |
| CVE-2024-3236 | MEDIUM | 5.4 | 0.3% | Jun 17, 2024 | The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which cou... |
| CVE-2024-6046 | — | — | — | Jun 17, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-6045 | HIGH | 8.8 | 6.3% | Jun 17, 2024 | Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on ... |
| CVE-2024-6044 | MEDIUM | 6.5 | 0.4% | Jun 17, 2024 | Certain models of D-Link wireless routers have a path traversal vulnerability. Unauthenticated attackers on the same loc... |
| CVE-2024-5163 | CRITICAL | 9.8 | 0.5% | Jun 17, 2024 | Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account secu... |
| CVE-2024-6043 | CRITICAL | 9.8 | 1.9% | Jun 17, 2024 | A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This af... |
| CVE-2024-6042 | CRITICAL | 9.8 | 0.6% | Jun 17, 2024 | A vulnerability was found in itsourcecode Real Estate Management System 1.0. It has been rated as critical. Affected by ... |
| CVE-2024-6041 | HIGH | 8.8 | 0.5% | Jun 16, 2024 | A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. Affected by this ... |
| CVE-2024-6039 | HIGH | 8.8 | 0.7% | Jun 16, 2024 | A vulnerability, which was classified as critical, was found in Feng Office 3.11.1.2. Affected is an unknown function of... |
| CVE-2024-34451 | CRITICAL | 9.1 | 0.8% | Jun 16, 2024 | Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X... |
| CVE-2024-38396 | CRITICAL | 9.8 | 1.7% | Jun 16, 2024 | An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in ... |
| CVE-2024-38468 | CRITICAL | 9.8 | 0.4% | Jun 16, 2024 | Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API. |
| CVE-2024-38467 | HIGH | 7.5 | 0.4% | Jun 16, 2024 | Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API... |
| CVE-2024-38466 | CRITICAL | 9.8 | 0.4% | Jun 16, 2024 | Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password. |
| CVE-2024-38465 | MEDIUM | 5.3 | 0.3% | Jun 16, 2024 | Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of i... |
| CVE-2024-38462 | CRITICAL | 9.8 | 0.6% | Jun 16, 2024 | iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mai... |
| CVE-2024-38461 | HIGH | 7.5 | 0.4% | Jun 16, 2024 | irodsServerMonPerf in iRODS before 4.3.2 attempts to proceed with use of a path even if it is not a directory. |
| CVE-2024-38460 | MEDIUM | 6.5 | 0.3% | Jun 16, 2024 | In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially... |
| CVE-2024-38459 | HIGH | 7.8 | 0.2% | Jun 16, 2024 | langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an o... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now