2024 CVE Vulnerabilities
39,241 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35712 | MEDIUM | 4.9 | 0.6% | Jun 10, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jordy Meow Database Clea... |
| CVE-2024-35680 | MEDIUM | 5.3 | 0.3% | Jun 10, 2024 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in YITHEMES YITH WooCommerce... |
| CVE-2024-35677 | CRITICAL | 9.8 | 0.5% | Jun 10, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes MegaMenu ... |
| CVE-2024-35658 | CRITICAL | 9.1 | 0.6% | Jun 10, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeHigh Checkout Field... |
| CVE-2024-35650 | HIGH | 7.2 | 0.6% | Jun 10, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-35474 | MEDIUM | 6.5 | 0.9% | Jun 10, 2024 | A Directory Traversal vulnerability in iceice666 ResourcePack Server before v1.0.8 allows a remote attacker to disclose ... |
| CVE-2024-34800 | HIGH | 7.6 | 0.3% | Jun 10, 2024 | Missing Authorization vulnerability in Crafthemes Crafthemes Demo Import crafthemes-demo-import allows Exploiting Incorr... |
| CVE-2024-34762 | CRITICAL | 9.9 | 0.6% | Jun 10, 2024 | Vulnerability discovered by executing a planned security audit. Improper Limitation of a Pathname to a Restricted Direc... |
| CVE-2024-34761 | HIGH | 8.5 | 0.4% | Jun 10, 2024 | Vulnerability discovered by executing a planned security audit. Improper Control of Generation of Code ('Code Injection... |
| CVE-2024-34332 | HIGH | 7.8 | 0.2% | Jun 10, 2024 | An issue in SiSoftware SANDRA v31.66 (SANDRA.sys 15.18.1.1) and before allows an attacker to escalate privileges via a c... |
| CVE-2024-31613 | MEDIUM | 5.4 | 0.2% | Jun 10, 2024 | BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code." |
| CVE-2024-26507 | HIGH | 7.8 | 0.2% | Jun 10, 2024 | An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit v.7.00.6700 and before allow... |
| CVE-2024-4403 | HIGH | 8.8 | 0.2% | Jun 10, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the restart_program function of the parisneo/lollms-webui v9... |
| CVE-2024-36972 | HIGH | 7.8 | 0.7% | Jun 10, 2024 | In the Linux kernel, the following vulnerability has been resolved: af_unix: Update unix_sk(sk)->oob_skb under sk_recei... |
| CVE-2024-36531 | MEDIUM | 5.7 | 0.4% | Jun 10, 2024 | nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admi... |
| CVE-2024-36528 | HIGH | 8.8 | 0.8% | Jun 10, 2024 | nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in co... |
| CVE-2024-36406 | MEDIUM | 5.4 | 0.3% | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and ... |
| CVE-2024-35307 | CRITICAL | 9.8 | 0.9% | Jun 10, 2024 | Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to e... |
| CVE-2024-35306 | CRITICAL | 9.8 | 0.9% | Jun 10, 2024 | OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This... |
| CVE-2024-35305 | CRITICAL | 9.8 | 0.4% | Jun 10, 2024 | Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora F... |
| CVE-2024-35304 | CRITICAL | 9.8 | 1.1% | Jun 10, 2024 | System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitr... |
| CVE-2024-5786 | MEDIUM | 6.5 | 0.2% | Jun 10, 2024 | Cross-Site Request Forgery vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This... |
| CVE-2024-5785 | HIGH | 8 | 0.9% | Jun 10, 2024 | Command injection vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerab... |
| CVE-2024-36405 | HIGH | 7.5 | 0.5% | Jun 10, 2024 | liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A co... |
| CVE-2024-3700 | CRITICAL | 9.8 | 0.4% | Jun 10, 2024 | Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the databas... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now