2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35338 | CRITICAL | 9.8 | 0.5% | Jul 16, 2024 | Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root. |
| CVE-2024-33182 | CRITICAL | 9.8 | 0.6% | Jul 16, 2024 | Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId paramet... |
| CVE-2024-33180 | CRITICAL | 9.8 | 0.6% | Jul 16, 2024 | Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId paramet... |
| CVE-2024-22442 | CRITICAL | 9.8 | 0.6% | Jul 16, 2024 | The vulnerability could be remotely exploited to bypass authentication. |
| CVE-2024-39887 | CRITICAL | 9.8 | 4.4% | Jul 16, 2024 | An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL ... |
| CVE-2024-40524 | CRITICAL | 9.8 | 1.4% | Jul 15, 2024 | Directory Traversal vulnerability in xmind2testcase v.1.5 allows a remote attacker to execute arbitrary code via the web... |
| CVE-2024-4143 | CRITICAL | 9.8 | 0.6% | Jul 15, 2024 | A potential security vulnerability has been identified in certain HP PC products using AMI BIOS, which might allow arbit... |
| CVE-2024-40624 | CRITICAL | 9.8 | 1.0% | Jul 15, 2024 | TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In `torrentpier/library/includes... |
| CVE-2024-39915 | CRITICAL | 9.9 | 0.6% | Jul 15, 2024 | Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the Livestatus API. This au... |
| CVE-2024-40416 | CRITICAL | 9.8 | 0.6% | Jul 15, 2024 | A vulnerability in /goform/SetVirtualServerCfg in the sub_6320C function in Tenda AX1806 1.0.0.1 firmware leads to stack... |
| CVE-2024-40415 | CRITICAL | 9.8 | 0.5% | Jul 15, 2024 | A vulnerability in /goform/SetStaticRouteCfg in the sub_519F4 function in Tenda AX1806 1.0.0.1 firmware leads to stack-b... |
| CVE-2024-40414 | CRITICAL | 9.8 | 0.5% | Jul 15, 2024 | A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmware leads to stack-b... |
| CVE-2024-38492 | CRITICAL | 9.4 | 0.9% | Jul 15, 2024 | This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by ... |
| CVE-2024-36456 | CRITICAL | 9.4 | 0.9% | Jul 15, 2024 | This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by ... |
| CVE-2024-36455 | CRITICAL | 9.4 | 0.5% | Jul 15, 2024 | An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM ... |
| CVE-2024-6745 | CRITICAL | 9.8 | 0.7% | Jul 15, 2024 | A vulnerability classified as critical has been found in code-projects Simple Ticket Booking 1.0. Affected is an unknown... |
| CVE-2024-6744 | CRITICAL | 9.8 | 0.8% | Jul 15, 2024 | The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Ove... |
| CVE-2024-6743 | CRITICAL | 9.8 | 0.7% | Jul 15, 2024 | AguardNet's Space Management System does not properly validate user input, allowing unauthenticated remote attackers to ... |
| CVE-2024-39736 | CRITICAL | 9.8 | 0.4% | Jul 15, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to HTTP header injection, caused by improper v... |
| CVE-2024-6728 | CRITICAL | 9.8 | 0.6% | Jul 14, 2024 | A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been classified as critical. This affe... |
| CVE-2024-5450 | CRITICAL | 9.1 | 0.8% | Jul 13, 2024 | The Bug Library WordPress plugin before 2.1.1 does not check the file type on user-submitted bug reports, allowing an un... |
| CVE-2024-40110 | CRITICAL | 9.8 | 1.9% | Jul 12, 2024 | Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability... |
| CVE-2024-40542 | CRITICAL | 9.8 | 0.4% | Jul 12, 2024 | my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para... |
| CVE-2024-40541 | CRITICAL | 9.8 | 0.4% | Jul 12, 2024 | my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para... |
| CVE-2024-40540 | CRITICAL | 9.8 | 0.5% | Jul 12, 2024 | my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now