2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-40539 | CRITICAL | 9.8 | 0.5% | Jul 12, 2024 | my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para... |
| CVE-2024-39917 | CRITICAL | 9.8 | 0.6% | Jul 12, 2024 | xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an i... |
| CVE-2024-38736 | CRITICAL | 9.1 | 0.5% | Jul 12, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Realtyna Realtyna Organic IDX plugin allows Code Inject... |
| CVE-2024-38734 | CRITICAL | 9.1 | 0.5% | Jul 12, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft... |
| CVE-2024-39914 | CRITICAL | 9.8 | 23.4% | Jul 12, 2024 | FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.... |
| CVE-2024-37933 | CRITICAL | 9.3 | 0.4% | Jul 12, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in anhvnit Woocommerc... |
| CVE-2024-37927 | CRITICAL | 9.8 | 0.5% | Jul 12, 2024 | Incorrect Privilege Assignment vulnerability in NooTheme Jobmonster noo-jobmonster allows Privilege Escalation.This issu... |
| CVE-2024-36522 | CRITICAL | 9.8 | 2.1% | Jul 12, 2024 | The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when proc... |
| CVE-2024-6328 | CRITICAL | 9.8 | 0.7% | Jul 12, 2024 | The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypa... |
| CVE-2024-6396 | CRITICAL | 9.8 | 53.4% | Jul 12, 2024 | A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any fi... |
| CVE-2024-36435 | CRITICAL | 9.8 | 1.3% | Jul 11, 2024 | An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM... |
| CVE-2024-6681 | CRITICAL | 9.8 | 0.5% | Jul 11, 2024 | A vulnerability, which was classified as critical, has been found in witmy my-springsecurity-plus up to 2024-07-04. Affe... |
| CVE-2024-6680 | CRITICAL | 9.8 | 0.5% | Jul 11, 2024 | A vulnerability classified as critical was found in witmy my-springsecurity-plus up to 2024-07-04. Affected by this vuln... |
| CVE-2024-6679 | CRITICAL | 9.8 | 0.6% | Jul 11, 2024 | A vulnerability classified as critical has been found in witmy my-springsecurity-plus up to 2024-07-04. Affected is an u... |
| CVE-2024-6624 | CRITICAL | 9.8 | 2.9% | Jul 11, 2024 | The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3... |
| CVE-2024-6385 | CRITICAL | 9.8 | 6.0% | Jul 11, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 p... |
| CVE-2024-6397 | CRITICAL | 9.8 | 0.7% | Jul 11, 2024 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all ... |
| CVE-2024-40618 | CRITICAL | 9.6 | 0.4% | Jul 11, 2024 | Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when pr... |
| CVE-2024-6653 | CRITICAL | 9.8 | 0.8% | Jul 11, 2024 | A vulnerability was found in code-projects Simple Task List 1.0. It has been declared as critical. This vulnerability af... |
| CVE-2024-6037 | CRITICAL | 9.1 | 10.6% | Jul 10, 2024 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any loc... |
| CVE-2024-6036 | CRITICAL | 9.1 | 10.8% | Jul 10, 2024 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending ... |
| CVE-2024-37310 | CRITICAL | 9 | 0.7% | Jul 10, 2024 | EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp... |
| CVE-2024-25077 | CRITICAL | 9.8 | 0.4% | Jul 10, 2024 | An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The Nonce used for on-the-f... |
| CVE-2024-5910 | CRITICAL | 9.8 | 91.7% | Jul 10, 2024 | Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account ... |
| CVE-2024-37770 | CRITICAL | 9.1 | 1.6% | Jul 10, 2024 | 14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now