2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6953 | CRITICAL | 9.8 | 0.5% | Jul 21, 2024 | A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects... |
| CVE-2024-6951 | CRITICAL | 9.8 | 0.5% | Jul 21, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Online Book Store System 1.0. This... |
| CVE-2024-6948 | CRITICAL | 9.8 | 0.5% | Jul 21, 2024 | A vulnerability classified as critical has been found in Gargaj wuhu up to 3faad49bfcc3895e9ff76a591d05c8941273d120. Aff... |
| CVE-2024-6945 | CRITICAL | 9.8 | 0.6% | Jul 21, 2024 | A vulnerability was found in Flute CMS 0.2.2.4-alpha. It has been classified as critical. This affects an unknown part o... |
| CVE-2024-38438 | CRITICAL | 9.8 | 0.7% | Jul 21, 2024 | D-Link - CWE-294: Authentication Bypass by Capture-replay |
| CVE-2024-38437 | CRITICAL | 9.8 | 0.7% | Jul 21, 2024 | D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel |
| CVE-2024-6933 | CRITICAL | 9.8 | 0.6% | Jul 21, 2024 | A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettin... |
| CVE-2024-6636 | CRITICAL | 9.8 | 0.5% | Jul 20, 2024 | The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ... |
| CVE-2024-41603 | CRITICAL | 9.6 | 0.2% | Jul 19, 2024 | Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout. |
| CVE-2024-39962 | CRITICAL | 9.8 | 2.1% | Jul 19, 2024 | D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (... |
| CVE-2024-29736 | CRITICAL | 9.1 | 1.0% | Jul 19, 2024 | A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attac... |
| CVE-2024-6205 | CRITICAL | 9.8 | 4.2% | Jul 19, 2024 | The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using... |
| CVE-2024-6899 | CRITICAL | 9.8 | 0.6% | Jul 19, 2024 | A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as critical. This vulnera... |
| CVE-2024-6898 | CRITICAL | 9.8 | 0.6% | Jul 19, 2024 | A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as critical. This affec... |
| CVE-2024-35198 | CRITICAL | 9.8 | 0.8% | Jul 19, 2024 | TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. TorchServe 's check ... |
| CVE-2024-39173 | CRITICAL | 9.8 | 0.8% | Jul 18, 2024 | calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function ... |
| CVE-2024-0857 | CRITICAL | 9.8 | 0.4% | Jul 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software... |
| CVE-2024-5619 | CRITICAL | 9.6 | 0.4% | Jul 18, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allo... |
| CVE-2024-5618 | CRITICAL | 9.9 | 0.4% | Jul 18, 2024 | Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console... |
| CVE-2024-40629 | CRITICAL | 9.8 | 1.3% | Jul 18, 2024 | JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand an... |
| CVE-2024-40628 | CRITICAL | 9.1 | 0.9% | Jul 18, 2024 | JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand an... |
| CVE-2024-39911 | CRITICAL | 9.8 | 4.6% | Jul 18, 2024 | 1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent... |
| CVE-2024-39907 | CRITICAL | 9.8 | 29.4% | Jul 18, 2024 | 1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of t... |
| CVE-2024-6164 | CRITICAL | 9.8 | 1.1% | Jul 18, 2024 | The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. T... |
| CVE-2024-41184 | CRITICAL | 9.8 | 0.6% | Jul 18, 2024 | In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now