2024 CVE Vulnerabilities
39,241 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36691 | MEDIUM | 6.3 | 0.3% | Jun 12, 2024 | Insecure permissions in the AdminController.AjaxSave() method of PPGo_Jobs v2.8.0 allows authenticated attackers to arbi... |
| CVE-2024-36265 | CRITICAL | 9.8 | 0.7% | Jun 12, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affec... |
| CVE-2024-34065 | HIGH | 8.1 | 0.7% | Jun 12, 2024 | Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session to... |
| CVE-2024-31217 | MEDIUM | 6.5 | 0.7% | Jun 12, 2024 | Strapi is an open-source content management system. Prior to version 4.22.0, a denial-of-service vulnerability is presen... |
| CVE-2024-2300 | MEDIUM | 6.2 | 0.2% | Jun 12, 2024 | HP Advance Mobile Applications for iOS and Android are potentially vulnerable to information disclosure when using an ou... |
| CVE-2024-29181 | LOW | 3.5 | 0.4% | Jun 12, 2024 | Strapi is an open-source content management system. Prior to version 4.19.1, a super admin can create a collection where... |
| CVE-2024-28964 | HIGH | 7.8 | 0.4% | Jun 12, 2024 | Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A... |
| CVE-2024-5891 | MEDIUM | 4.2 | 0.2% | Jun 12, 2024 | A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth tok... |
| CVE-2024-36699 | — | — | — | Jun 12, 2024 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2024-36264 | CRITICAL | 9.8 | 1.0% | Jun 12, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user do... |
| CVE-2024-36263 | HIGH | 8.1 | 1.0% | Jun 12, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vul... |
| CVE-2024-23445 | MEDIUM | 6.5 | 0.5% | Jun 12, 2024 | It was identified that if a cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security... |
| CVE-2024-1659 | CRITICAL | 9.8 | 0.7% | Jun 12, 2024 | Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PH... |
| CVE-2024-1577 | CRITICAL | 9.8 | 1.1% | Jun 12, 2024 | Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring... |
| CVE-2024-1576 | CRITICAL | 9.8 | 0.6% | Jun 12, 2024 | SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including acces... |
| CVE-2024-5313 | MEDIUM | 6.5 | 0.4% | Jun 12, 2024 | CWE-668: Exposure of the Resource Wrong Sphere vulnerability exists that exposes a SSH interface over the product networ... |
| CVE-2024-25949 | HIGH | 8.8 | 0.4% | Jun 12, 2024 | Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vuln... |
| CVE-2024-5211 | HIGH | 7.2 | 1.0% | Jun 12, 2024 | A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function,... |
| CVE-2024-5056 | MEDIUM | 6.5 | 0.3% | Jun 12, 2024 | CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may prevent user to update the d... |
| CVE-2024-5674 | MEDIUM | 6.5 | 0.3% | Jun 12, 2024 | The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PH... |
| CVE-2024-4898 | CRITICAL | 9.8 | 4.2% | Jun 12, 2024 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due ... |
| CVE-2024-3492 | MEDIUM | 5.4 | 0.3% | Jun 12, 2024 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2024-1766 | MEDIUM | 5.4 | 0.3% | Jun 12, 2024 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all ... |
| CVE-2024-4845 | HIGH | 8.8 | 0.5% | Jun 12, 2024 | The Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘options[list_id]’ parameter in all vers... |
| CVE-2024-2092 | MEDIUM | 5.4 | 0.3% | Jun 12, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now