2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39226 | CRITICAL | 9.8 | 20.6% | Aug 6, 2024 | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/... |
| CVE-2024-39225 | CRITICAL | 9.8 | 14.5% | Aug 6, 2024 | GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/... |
| CVE-2024-23483 | CRITICAL | 9.8 | 0.7% | Aug 6, 2024 | An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue ... |
| CVE-2024-33897 | CRITICAL | 9.1 | 0.7% | Aug 6, 2024 | A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another d... |
| CVE-2024-30170 | CRITICAL | 9.1 | 0.6% | Aug 6, 2024 | PrivX before 34.0 allows data exfiltration and denial of service via the REST API. This is fixed in minor versions 33.1,... |
| CVE-2024-7519 | CRITICAL | 9.6 | 0.6% | Aug 6, 2024 | Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged ... |
| CVE-2024-6359 | CRITICAL | 9.8 | 0.3% | Aug 6, 2024 | Privilege escalation vulnerability identified in OpenText ArcSight Intelligence. |
| CVE-2024-33974 | CRITICAL | 9.8 | 0.4% | Aug 6, 2024 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could explo... |
| CVE-2024-33960 | CRITICAL | 9.8 | 0.5% | Aug 6, 2024 | SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could explo... |
| CVE-2024-6202 | CRITICAL | 9.8 | 0.5% | Aug 6, 2024 | HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML in... |
| CVE-2024-7505 | CRITICAL | 9.8 | 0.7% | Aug 6, 2024 | A vulnerability, which was classified as critical, was found in itsourcecode Bike Delivery System 1.0. Affected is an un... |
| CVE-2024-7500 | CRITICAL | 9.8 | 0.7% | Aug 6, 2024 | A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been rated as critical. Affected by thi... |
| CVE-2024-6886 | CRITICAL | 10 | 28.2% | Aug 6, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea... |
| CVE-2024-6782 | CRITICAL | 9.8 | 83.4% | Aug 6, 2024 | Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution. |
| CVE-2024-7499 | CRITICAL | 9.8 | 0.6% | Aug 6, 2024 | A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been declared as critical. Affected by ... |
| CVE-2024-7498 | CRITICAL | 9.8 | 0.7% | Aug 6, 2024 | A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been classified as critical. Affected i... |
| CVE-2024-5828 | CRITICAL | 9.8 | 0.4% | Aug 6, 2024 | Expression Language Injection vulnerability in Hitachi Tuning Manager on Windows, Linux, Solaris allows Code Injection.T... |
| CVE-2024-7495 | CRITICAL | 9.8 | 0.6% | Aug 6, 2024 | A vulnerability, which was classified as critical, was found in itsourcecode Laravel Accounting System 1.0. This affects... |
| CVE-2024-7494 | CRITICAL | 9.8 | 0.6% | Aug 5, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Clinics Patient Management System 1.... |
| CVE-2024-6915 | CRITICAL | 9.3 | 0.6% | Aug 5, 2024 | JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to... |
| CVE-2024-42009 | CRITICAL | 9.3 | 82.9% | Aug 5, 2024 | A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to stea... |
| CVE-2024-42008 | CRITICAL | 9.3 | 32.3% | Aug 5, 2024 | A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7... |
| CVE-2024-40498 | CRITICAL | 9.8 | 1.0% | Aug 5, 2024 | SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbit... |
| CVE-2024-7397 | CRITICAL | 9.3 | 1.4% | Aug 5, 2024 | Improper filering of special characters result in a command ('command injection') vulnerability in Korenix JetPort 5601v... |
| CVE-2024-7395 | CRITICAL | 9.3 | 0.9% | Aug 5, 2024 | An authentication bypass vulnerability in Korenix JetPort 5601v3 allows an attacker to access functionality on the devic... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now