2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37313 | HIGH | 7.5 | 0.4% | Jun 14, 2024 | Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second fa... |
| CVE-2024-37312 | MEDIUM | 6.3 | 0.6% | Jun 14, 2024 | user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an at... |
| CVE-2024-36656 | MEDIUM | 6.1 | 0.3% | Jun 14, 2024 | In MintHCM 4.0.3, a registered user can execute arbitrary JavaScript code and achieve a reflected Cross-site Scripting (... |
| CVE-2024-34694 | HIGH | 8.1 | 0.6% | Jun 14, 2024 | LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal ... |
| CVE-2024-34539 | CRITICAL | 9.4 | 0.5% | Jun 14, 2024 | Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail ... |
| CVE-2024-33377 | HIGH | 8.1 | 0.4% | Jun 14, 2024 | LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attacker... |
| CVE-2024-33375 | CRITICAL | 9.8 | 0.6% | Jun 14, 2024 | LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware. |
| CVE-2024-33374 | CRITICAL | 9.8 | 0.5% | Jun 14, 2024 | Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access th... |
| CVE-2024-23442 | MEDIUM | 6.1 | 0.3% | Jun 14, 2024 | An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if th... |
| CVE-2024-5731 | MEDIUM | 6.8 | 0.3% | Jun 14, 2024 | A vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to cont... |
| CVE-2024-5671 | CRITICAL | 9.8 | 0.9% | Jun 14, 2024 | Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitra... |
| CVE-2024-37640 | HIGH | 8.8 | 0.6% | Jun 14, 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWiFiEasyG... |
| CVE-2024-37639 | HIGH | 8.8 | 0.6% | Jun 14, 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via eport in the function setIpPortFilt... |
| CVE-2024-37637 | CRITICAL | 9.8 | 0.7% | Jun 14, 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWizardCfg... |
| CVE-2024-2024 | HIGH | 8.8 | 3.3% | Jun 14, 2024 | The Folders Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ... |
| CVE-2024-2023 | MEDIUM | 4.3 | 0.7% | Jun 14, 2024 | The Folders and Folders Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includi... |
| CVE-2024-36459 | HIGH | 8.4 | 0.4% | Jun 14, 2024 | A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for ... |
| CVE-2024-5685 | HIGH | 8.1 | 0.4% | Jun 14, 2024 | Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes ... |
| CVE-2024-3912 | CRITICAL | 9.8 | 1.0% | Jun 14, 2024 | Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can e... |
| CVE-2024-34012 | MEDIUM | 4.4 | 0.1% | Jun 14, 2024 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manage... |
| CVE-2024-2472 | CRITICAL | 9.1 | 0.6% | Jun 14, 2024 | The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a... |
| CVE-2024-5996 | — | — | — | Jun 14, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-4863 | MEDIUM | 5.4 | 0.5% | Jun 14, 2024 | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si... |
| CVE-2024-37182 | MEDIUM | 6.1 | 0.3% | Jun 14, 2024 | Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows ... |
| CVE-2024-36287 | LOW | 3.3 | 0.2% | Jun 14, 2024 | Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC rest... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now