2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37113 | CRITICAL | 9.8 | 0.5% | Jul 10, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This i... |
| CVE-2024-5217 | CRITICAL | 9.8 | 99.6% | Jul 10, 2024 | ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earl... |
| CVE-2024-4879 | CRITICAL | 9.8 | 100.0% | Jul 10, 2024 | ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platfo... |
| CVE-2024-6422 | CRITICAL | 9.8 | 0.6% | Jul 10, 2024 | An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data. |
| CVE-2024-21524 | CRITICAL | 9.1 | 0.8% | Jul 10, 2024 | All versions of the package node-stringbuilder are vulnerable to Out-of-bounds Read due to incorrect memory length calcu... |
| CVE-2024-39071 | CRITICAL | 9.8 | 0.8% | Jul 9, 2024 | Fujian Kelixun <=7.6.6.4391 is vulnerable to SQL Injection in send_event.php. |
| CVE-2024-37873 | CRITICAL | 9.8 | 0.7% | Jul 9, 2024 | SQL injection vulnerability in view_payslip.php in Itsourcecode Payroll Management System Project In PHP With Source Cod... |
| CVE-2024-37870 | CRITICAL | 9.8 | 0.5% | Jul 9, 2024 | SQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows... |
| CVE-2024-39171 | CRITICAL | 9.8 | 1.2% | Jul 9, 2024 | Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code ... |
| CVE-2024-38089 | CRITICAL | 9.9 | 1.2% | Jul 9, 2024 | Microsoft Defender for IoT Elevation of Privilege Vulnerability |
| CVE-2024-38077 | CRITICAL | 9.8 | 75.4% | Jul 9, 2024 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
| CVE-2024-38076 | CRITICAL | 9.8 | 2.2% | Jul 9, 2024 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
| CVE-2024-38074 | CRITICAL | 9.8 | 2.2% | Jul 9, 2024 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
| CVE-2024-36526 | CRITICAL | 9.8 | 0.9% | Jul 9, 2024 | ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key. |
| CVE-2024-27782 | CRITICAL | 9.8 | 0.7% | Jul 9, 2024 | Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an at... |
| CVE-2024-6611 | CRITICAL | 9.8 | 0.7% | Jul 9, 2024 | A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affec... |
| CVE-2024-6602 | CRITICAL | 9.8 | 1.0% | Jul 9, 2024 | A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 1... |
| CVE-2024-6527 | CRITICAL | 9.3 | 0.6% | Jul 9, 2024 | SQL Injection vulnerability in parameter "w" in file "druk.php" in MegaBIP software allows unauthorized attacker to disc... |
| CVE-2024-37934 | CRITICAL | 9.8 | 0.5% | Jul 9, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Inject... |
| CVE-2024-3596 | CRITICAL | 9 | 14.9% | Jul 9, 2024 | RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (... |
| CVE-2024-39872 | CRITICAL | 9.9 | 0.5% | Jul 9, 2024 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application ... |
| CVE-2024-37424 | CRITICAL | 9.9 | 0.5% | Jul 9, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Automattic Newspack Blocks allows Upload a Web Shell to... |
| CVE-2024-37420 | CRITICAL | 9.9 | 0.5% | Jul 9, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in WPZita Zita Elementor Site Library allows Upload a Web ... |
| CVE-2024-37418 | CRITICAL | 9.9 | 0.5% | Jul 9, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects... |
| CVE-2024-37112 | CRITICAL | 9.8 | 0.5% | Jul 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Membership Softwar... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now