2024 CVE Vulnerabilities
39,242 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31629 | — | — | — | Jun 5, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-31628 | — | — | — | Jun 5, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-31627 | — | — | — | Jun 5, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-31626 | — | — | — | Jun 5, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-31625 | — | — | — | Jun 5, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-31624 | — | — | — | Jun 5, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-31623 | — | — | — | Jun 5, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-31622 | — | — | — | Jun 5, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-20405 | MEDIUM | 6.1 | 0.6% | Jun 5, 2024 | A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t... |
| CVE-2024-20404 | MEDIUM | 5.3 | 23.1% | Jun 5, 2024 | A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t... |
| CVE-2024-24790 | CRITICAL | 9.8 | 2.0% | Jun 5, 2024 | The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning f... |
| CVE-2024-24789 | MEDIUM | 5.5 | 0.4% | Jun 5, 2024 | The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implement... |
| CVE-2024-5629 | HIGH | 8.1 | 0.7% | Jun 5, 2024 | An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided... |
| CVE-2024-4812 | MEDIUM | 4.8 | 0.3% | Jun 5, 2024 | A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Desc... |
| CVE-2024-3716 | MEDIUM | 6.2 | 0.2% | Jun 5, 2024 | A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue le... |
| CVE-2024-36837 | HIGH | 7.5 | 8.3% | Jun 5, 2024 | SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getProduct... |
| CVE-2024-35673 | MEDIUM | 4.3 | 0.2% | Jun 5, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Pure Chat by Ruby Pure Chat.This issue affects Pure Chat: from n/a th... |
| CVE-2024-5459 | MEDIUM | 4.3 | 0.4% | Jun 5, 2024 | The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missi... |
| CVE-2024-3469 | MEDIUM | 6.1 | 0.6% | Jun 5, 2024 | The GP Premium plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the message parameter in all ver... |
| CVE-2024-5526 | CRITICAL | 9.1 | 0.4% | Jun 5, 2024 | Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simple... |
| CVE-2024-1662 | HIGH | 7.5 | 0.4% | Jun 5, 2024 | Missing Authentication for Critical Function, Missing Authorization vulnerability in PORTY Smart Tech Technology Joint S... |
| CVE-2024-4001 | MEDIUM | 5.4 | 0.3% | Jun 5, 2024 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_logi... |
| CVE-2024-5536 | MEDIUM | 5.4 | 0.3% | Jun 5, 2024 | The GamiPress – Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's gamipress_link s... |
| CVE-2024-5571 | MEDIUM | 5.4 | 0.3% | Jun 5, 2024 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gute... |
| CVE-2024-4821 | MEDIUM | 5.4 | 0.3% | Jun 5, 2024 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now