2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42256 | CRITICAL | 9.8 | 0.7% | Aug 8, 2024 | In the Linux kernel, the following vulnerability has been resolved: cifs: Fix server re-repick on subrequest retry Whe... |
| CVE-2024-7350 | CRITICAL | 9.8 | 0.7% | Aug 8, 2024 | The Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress plugin for WordPress is vulnerable t... |
| CVE-2024-41912 | CRITICAL | 9.8 | 0.5% | Aug 7, 2024 | A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw... |
| CVE-2024-41237 | CRITICAL | 9.8 | 0.6% | Aug 7, 2024 | A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an... |
| CVE-2024-7585 | CRITICAL | 9.8 | 1.3% | Aug 7, 2024 | A vulnerability has been found in Tenda i22 1.0.0.3(4687) and classified as critical. Affected by this vulnerability is ... |
| CVE-2024-7584 | CRITICAL | 9.8 | 1.3% | Aug 7, 2024 | A vulnerability, which was classified as critical, was found in Tenda i22 1.0.0.3(4687). Affected is the function formAp... |
| CVE-2024-20454 | CRITICAL | 9.8 | 6.6% | Aug 7, 2024 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco... |
| CVE-2024-20450 | CRITICAL | 9.8 | 7.2% | Aug 7, 2024 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco... |
| CVE-2024-7583 | CRITICAL | 9.8 | 1.4% | Aug 7, 2024 | A vulnerability, which was classified as critical, has been found in Tenda i22 1.0.0.3(4687). This issue affects the fun... |
| CVE-2024-7582 | CRITICAL | 9.8 | 1.4% | Aug 7, 2024 | A vulnerability classified as critical was found in Tenda i22 1.0.0.3(4687). This vulnerability affects the function for... |
| CVE-2024-34480 | CRITICAL | 9.8 | 0.6% | Aug 7, 2024 | SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection. |
| CVE-2024-34479 | CRITICAL | 9.8 | 0.7% | Aug 7, 2024 | SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection. |
| CVE-2024-7581 | CRITICAL | 9.8 | 1.4% | Aug 7, 2024 | A vulnerability classified as critical has been found in Tenda A301 15.13.08.12. This affects the function formWifiBasic... |
| CVE-2024-7580 | CRITICAL | 9.8 | 8.9% | Aug 7, 2024 | A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been rated as critical. Affected by thi... |
| CVE-2024-7578 | CRITICAL | 9.8 | 0.8% | Aug 7, 2024 | A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been classified as critical. Affected i... |
| CVE-2024-6522 | CRITICAL | 9.6 | 0.4% | Aug 7, 2024 | The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and ... |
| CVE-2024-36130 | CRITICAL | 9.8 | 2.3% | Aug 7, 2024 | An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker w... |
| CVE-2024-41270 | CRITICAL | 9.1 | 0.3% | Aug 6, 2024 | An issue discovered in the RunHTTPServer function in Gorush v1.18.4 allows attackers to intercept and manipulate data du... |
| CVE-2024-42395 | CRITICAL | 9.8 | 0.4% | Aug 6, 2024 | There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthe... |
| CVE-2024-42394 | CRITICAL | 9.8 | 0.6% | Aug 6, 2024 | There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated R... |
| CVE-2024-42393 | CRITICAL | 9.8 | 0.6% | Aug 6, 2024 | There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated R... |
| CVE-2024-28740 | CRITICAL | 9.6 | 0.7% | Aug 6, 2024 | Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via t... |
| CVE-2024-39227 | CRITICAL | 9.8 | 1.2% | Aug 6, 2024 | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/... |
| CVE-2024-41616 | CRITICAL | 9.8 | 0.8% | Aug 6, 2024 | D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service. |
| CVE-2024-39228 | CRITICAL | 9.8 | 0.7% | Aug 6, 2024 | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now