2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-28060 | HIGH | 7.3 | 0.2% | May 28, 2024 | An issue was discovered in Apiris Kafeo 6.4.4. It permits DLL hijacking, allowing a user to trigger the execution of arb... |
| CVE-2024-5434 | MEDIUM | 6.9 | 0.2% | May 28, 2024 | The Campbell Scientific CSI Web Server stores web authentication credentials in a file with a specific file name. Passwo... |
| CVE-2024-5433 | MEDIUM | 5.3 | 0.5% | May 28, 2024 | The Campbell Scientific CSI Web Server supports a command that will return the most recent file that matches a given exp... |
| CVE-2024-36110 | HIGH | 8.2 | 0.4% | May 28, 2024 | ansibleguy-webui is an open source WebUI for using Ansible. Multiple forms in versions < 0.0.21 allowed injection of HTM... |
| CVE-2024-36109 | HIGH | 7.6 | 0.4% | May 28, 2024 | CoCalc is web-based software that enables collaboration in research, teaching, and scientific publishing. In affected ve... |
| CVE-2024-36107 | MEDIUM | 5.3 | 0.5% | May 28, 2024 | MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. `If-Modified-Since` an... |
| CVE-2024-33450 | HIGH | 7.5 | 0.5% | May 28, 2024 | SQL Injection in Finereport v.8.0 allows a remote attacker to obtain sensitive information |
| CVE-2024-24919 | HIGH | 8.6 | 100.0% | May 28, 2024 | Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the inte... |
| CVE-2024-33402 | HIGH | 8.1 | 0.4% | May 28, 2024 | A SQL injection vulnerability in /model/approve_petty_cash.php in campcodes Complete Web-Based School Management System ... |
| CVE-2024-35563 | CRITICAL | 9.8 | 0.5% | May 28, 2024 | CDG-Server-V5.6.2.126.139 and earlier was discovered to contain a SQL injection vulnerability via the permissionId param... |
| CVE-2024-35403 | LOW | 2.7 | 0.4% | May 28, 2024 | TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function... |
| CVE-2024-35401 | MEDIUM | 5.9 | 0.7% | May 28, 2024 | TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName para... |
| CVE-2024-35344 | CRITICAL | 9.9 | 0.4% | May 28, 2024 | Certain Anpviz products contain a hardcoded cryptographic key stored in the firmware of the device. This affects IPC-D25... |
| CVE-2024-35343 | CRITICAL | 9.8 | 0.5% | May 28, 2024 | Certain Anpviz products allow unauthenticated users to download arbitrary files from the device's filesystem via a HTTP ... |
| CVE-2024-35342 | MEDIUM | 4.6 | 0.2% | May 28, 2024 | Certain Anpviz products allow unauthenticated users to modify or disable camera related settings such as microphone volu... |
| CVE-2024-35341 | HIGH | 7.5 | 0.4% | May 28, 2024 | Certain Anpviz products allow unauthenticated users to download the running configuration of the device via a HTTP GET r... |
| CVE-2024-34854 | CRITICAL | 9.8 | 12.8% | May 28, 2024 | F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.` |
| CVE-2024-34852 | MEDIUM | 6.3 | 1.6% | May 28, 2024 | F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point ... |
| CVE-2024-30165 | HIGH | 7.1 | 0.2% | May 28, 2024 | Amazon AWS Client VPN before 3.9.1 on macOS has a buffer overflow that could potentially allow a local actor to execute ... |
| CVE-2024-30164 | MEDIUM | 6.7 | 0.3% | May 28, 2024 | Amazon AWS Client VPN has a buffer overflow that could potentially allow a local actor to execute arbitrary commands wit... |
| CVE-2024-26024 | HIGH | 8.6 | 0.2% | May 28, 2024 | SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in Substation Server. |
| CVE-2024-36472 | MEDIUM | 6.5 | 0.3% | May 28, 2024 | In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network ... |
| CVE-2024-35621 | MEDIUM | 4.8 | 0.3% | May 28, 2024 | A cross-site scripting (XSS) vulnerability in the Edit function of Formwork before 1.13.0 allows attackers to execute ar... |
| CVE-2024-35324 | CRITICAL | 9.8 | 2.1% | May 28, 2024 | Douchat 4.0.5 suffers from an arbitrary file upload vulnerability via Public/Plugins/webuploader/server/preview.php. |
| CVE-2024-33849 | MEDIUM | 6.5 | 0.4% | May 28, 2024 | ci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now