2024 CVE Vulnerabilities
39,242 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4870 | HIGH | 7.2 | 0.5% | Jun 4, 2024 | The Frontend Registration – Contact Form 7 plugin for WordPress is vulnerable to privilege escalation in versions up to,... |
| CVE-2024-4552 | CRITICAL | 9.8 | 0.6% | Jun 4, 2024 | The Social Login Lite For WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and... |
| CVE-2024-29976 | MEDIUM | 6.5 | 9.0% | Jun 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyx... |
| CVE-2024-29975 | MEDIUM | 6.7 | 0.5% | Jun 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel N... |
| CVE-2024-29974 | CRITICAL | 9.8 | 22.8% | Jun 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NA... |
| CVE-2024-29973 | CRITICAL | 9.8 | 86.2% | Jun 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar... |
| CVE-2024-29972 | CRITICAL | 9.8 | 89.2% | Jun 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326... |
| CVE-2024-36782 | CRITICAL | 9.8 | 0.4% | Jun 3, 2024 | TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, whic... |
| CVE-2024-36783 | CRITICAL | 9.8 | 1.4% | Jun 3, 2024 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the N... |
| CVE-2024-34987 | CRITICAL | 9.1 | 0.6% | Jun 3, 2024 | A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2... |
| CVE-2024-34051 | MEDIUM | 4.6 | 12.0% | Jun 3, 2024 | A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.... |
| CVE-2024-31682 | CRITICAL | 9.8 | 0.5% | Jun 3, 2024 | Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attac... |
| CVE-2024-5388 | — | — | — | Jun 3, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-5387 | — | — | — | Jun 3, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-5214 | — | — | — | Jun 3, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-31684 | LOW | 3.5 | 0.2% | Jun 3, 2024 | Incorrect access control in the fingerprint authentication mechanism of Bitdefender Mobile Security v4.11.3-gms allows a... |
| CVE-2024-4332 | CRITICAL | 9.3 | 0.6% | Jun 3, 2024 | An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (T... |
| CVE-2024-37019 | CRITICAL | 9.8 | 0.6% | Jun 3, 2024 | Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication. |
| CVE-2024-4540 | HIGH | 7.5 | 0.6% | Jun 3, 2024 | A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to ... |
| CVE-2024-36674 | MEDIUM | 6.1 | 0.3% | Jun 3, 2024 | LyLme_spage v1.9.5 is vulnerable to Cross Site Scripting (XSS) via admin/link.php. |
| CVE-2024-32983 | HIGH | 7.5 | 0.4% | Jun 3, 2024 | Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSO... |
| CVE-2024-36128 | HIGH | 7.5 | 0.6% | Jun 3, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.2, providing a non-numer... |
| CVE-2024-36127 | HIGH | 7.5 | 0.4% | Jun 3, 2024 | apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in l... |
| CVE-2024-36124 | MEDIUM | 5.3 | 0.5% | Jun 3, 2024 | iq80 Snappy is a compression/decompression library. When uncompressing certain data, Snappy tries to read outside the bo... |
| CVE-2024-36123 | MEDIUM | 5.4 | 0.5% | Jun 3, 2024 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page `MediaWiki:Tagline` has its ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now