2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41610 | CRITICAL | 9.8 | 0.9% | Jul 30, 2024 | D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attacker... |
| CVE-2024-39012 | CRITICAL | 9.8 | 1.0% | Jul 30, 2024 | ais-ltd strategyen v0.4.0 was discovered to contain a prototype pollution via the function mergeObjects. This vulnerabil... |
| CVE-2024-39011 | CRITICAL | 9.8 | 0.9% | Jul 30, 2024 | Prototype Pollution in chargeover redoc v2.0.9-rc.69 allows attackers to execute arbitrary code or cause a Denial of Ser... |
| CVE-2024-39010 | CRITICAL | 9.8 | 0.9% | Jul 30, 2024 | chase-moskal snapstate v0.0.9 was discovered to contain a prototype pollution via the function attemptNestedProperty. Th... |
| CVE-2024-38986 | CRITICAL | 9.8 | 1.0% | Jul 30, 2024 | Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (Do... |
| CVE-2024-38984 | CRITICAL | 9.8 | 1.0% | Jul 30, 2024 | Prototype Pollution in lukebond json-override 0.2.0 allows attackers to to execute arbitrary code or cause a Denial of S... |
| CVE-2024-36572 | CRITICAL | 9.8 | 0.7% | Jul 30, 2024 | Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the ... |
| CVE-2024-3930 | CRITICAL | 9.8 | 0.3% | Jul 30, 2024 | In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered. |
| CVE-2024-38909 | CRITICAL | 9.8 | 0.5% | Jul 30, 2024 | Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension betwee... |
| CVE-2024-6699 | CRITICAL | 9.8 | 0.4% | Jul 30, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mikafon Electronic... |
| CVE-2024-41702 | CRITICAL | 9.8 | 0.5% | Jul 30, 2024 | SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
| CVE-2024-38432 | CRITICAL | 9.8 | 0.2% | Jul 30, 2024 | Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File |
| CVE-2024-7224 | CRITICAL | 9.8 | 0.5% | Jul 30, 2024 | A vulnerability was found in SourceCodester Lot Reservation Management System 1.0 and classified as critical. Affected b... |
| CVE-2024-7223 | CRITICAL | 9.8 | 0.5% | Jul 30, 2024 | A vulnerability has been found in SourceCodester Lot Reservation Management System 1.0 and classified as critical. Affec... |
| CVE-2024-7222 | CRITICAL | 9.8 | 0.6% | Jul 30, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Lot Reservation Management System 1.0. Af... |
| CVE-2024-7221 | CRITICAL | 9.8 | 0.6% | Jul 30, 2024 | A vulnerability was determined in SourceCodester/Campcodes School Log Management System 1.0. This affects an unknown par... |
| CVE-2024-7220 | CRITICAL | 9.8 | 0.6% | Jul 30, 2024 | A vulnerability was found in SourceCodester/Campcodes School Log Management System 1.0. Affected by this issue is some u... |
| CVE-2024-7219 | CRITICAL | 9.8 | 0.8% | Jul 30, 2024 | A vulnerability has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected by this vulnerabil... |
| CVE-2024-5975 | CRITICAL | 9.1 | 2.0% | Jul 30, 2024 | The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in... |
| CVE-2024-5765 | CRITICAL | 9.8 | 27.4% | Jul 30, 2024 | The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a S... |
| CVE-2024-37858 | CRITICAL | 9.8 | 0.9% | Jul 29, 2024 | SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via... |
| CVE-2024-28805 | CRITICAL | 9.1 | 0.4% | Jul 29, 2024 | An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control. |
| CVE-2024-41799 | CRITICAL | 9.9 | 1.2% | Jul 29, 2024 | tgstation-server is a production scale tool for BYOND server management. Prior to 6.8.0, low permission users using the ... |
| CVE-2024-6576 | CRITICAL | 9.8 | 0.6% | Jul 29, 2024 | Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This is... |
| CVE-2024-7196 | CRITICAL | 9.8 | 0.6% | Jul 29, 2024 | A vulnerability was found in SourceCodester Complaints Report Management System 1.0. It has been declared as critical. A... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now