2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42470 | CRITICAL | 9.1 | 0.5% | Aug 12, 2024 | openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. S... |
| CVE-2024-42469 | CRITICAL | 9.8 | 1.2% | Aug 12, 2024 | openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. P... |
| CVE-2024-42467 | CRITICAL | 10 | 1.0% | Aug 12, 2024 | openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. I... |
| CVE-2024-42001 | CRITICAL | 9.8 | 0.7% | Aug 12, 2024 | An improper authentication vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeate... |
| CVE-2024-41577 | CRITICAL | 9.8 | 1.0% | Aug 12, 2024 | An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arb... |
| CVE-2024-41570 | CRITICAL | 9.8 | 2.9% | Aug 12, 2024 | An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send... |
| CVE-2024-41476 | CRITICAL | 9.8 | 0.6% | Aug 12, 2024 | AMTT Hotel Broadband Operation System (HiBOS) V3.0.3.151204 and before is vulnerable to SQL Injection via /manager/card/... |
| CVE-2024-40486 | CRITICAL | 9.8 | 1.0% | Aug 12, 2024 | A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execut... |
| CVE-2024-40482 | CRITICAL | 9.8 | 1.2% | Aug 12, 2024 | An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System... |
| CVE-2024-40480 | CRITICAL | 9.8 | 0.5% | Aug 12, 2024 | A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam S... |
| CVE-2024-40477 | CRITICAL | 9.8 | 0.8% | Aug 12, 2024 | A SQL injection vulnerability in "/oahms/admin/forgot-password.php" in PHPGurukul Old Age Home Management System v1.0 al... |
| CVE-2024-40472 | CRITICAL | 9.8 | 0.6% | Aug 12, 2024 | Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php." |
| CVE-2024-3279 | CRITICAL | 9.1 | 0.6% | Aug 12, 2024 | An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the i... |
| CVE-2024-39791 | CRITICAL | 9.8 | 1.1% | Aug 12, 2024 | Stack-based buffer overflow vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeat... |
| CVE-2024-38989 | CRITICAL | 9.8 | 1.1% | Aug 12, 2024 | izatop bunt v0.29.19 was discovered to contain a prototype pollution via the component /esm/qs.js. This vulnerability al... |
| CVE-2024-38219 | CRITICAL | 9 | 0.9% | Aug 12, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2024-37023 | CRITICAL | 9.9 | 1.3% | Aug 12, 2024 | Multiple OS command injection vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeater... |
| CVE-2024-22122 | CRITICAL | 9.1 | 1.6% | Aug 12, 2024 | Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validat... |
| CVE-2024-21878 | CRITICAL | 9.8 | 1.4% | Aug 12, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway ... |
| CVE-2024-21876 | CRITICAL | 9.1 | 0.8% | Aug 12, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enph... |
| CVE-2024-41161 | CRITICAL | 9.8 | 0.6% | Aug 8, 2024 | Use of hard-coded credentials vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, so... |
| CVE-2024-42366 | CRITICAL | 9 | 0.7% | Aug 8, 2024 | VRCX is an assistant/companion application for VRChat. In versions prior to 2024.03.23, a CefSharp browser with over-per... |
| CVE-2024-7490 | CRITICAL | 9.8 | 1.4% | Aug 8, 2024 | Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause... |
| CVE-2024-42357 | CRITICAL | 9.8 | 0.6% | Aug 8, 2024 | Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a s... |
| CVE-2024-42355 | CRITICAL | 9.8 | 0.9% | Aug 8, 2024 | Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages wh... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now