2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6314 | CRITICAL | 9.8 | 0.9% | Jul 9, 2024 | The IQ Testimonials plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validatio... |
| CVE-2024-6313 | CRITICAL | 9.8 | 1.1% | Jul 9, 2024 | The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowe... |
| CVE-2024-37555 | CRITICAL | 9.8 | 0.6% | Jul 9, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-p... |
| CVE-2024-28751 | CRITICAL | 9.1 | 0.6% | Jul 9, 2024 | An high privileged remote attacker can enable telnet access that accepts hardcoded credentials. |
| CVE-2024-28747 | CRITICAL | 9.8 | 0.7% | Jul 9, 2024 | An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privilege... |
| CVE-2024-5488 | CRITICAL | 9.8 | 3.8% | Jul 9, 2024 | The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with ano... |
| CVE-2024-6365 | CRITICAL | 9.8 | 1.2% | Jul 9, 2024 | The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin... |
| CVE-2024-1305 | CRITICAL | 9.8 | 15.4% | Jul 8, 2024 | tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which ... |
| CVE-2024-39677 | CRITICAL | 9.8 | 0.6% | Jul 8, 2024 | NHibernate is an object-relational mapper for the .NET framework. A SQL injection vulnerability exists in some types imp... |
| CVE-2024-39742 | CRITICAL | 9.8 | 0.8% | Jul 8, 2024 | IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configuration... |
| CVE-2024-27903 | CRITICAL | 9.8 | 8.9% | Jul 8, 2024 | OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker ... |
| CVE-2024-40614 | CRITICAL | 9.8 | 0.7% | Jul 7, 2024 | EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplat... |
| CVE-2024-37260 | CRITICAL | 9.3 | 0.3% | Jul 6, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Theme-Ruby Foxiz.This issue affects Foxiz: from n/a through 2.3.5. |
| CVE-2024-27712 | CRITICAL | 9.8 | 0.6% | Jul 5, 2024 | An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile... |
| CVE-2024-27710 | CRITICAL | 9.8 | 0.6% | Jul 5, 2024 | An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile... |
| CVE-2024-27709 | CRITICAL | 9.8 | 0.6% | Jul 5, 2024 | SQL Injection vulnerability in Eskooly Web Product v.3.0 allows a remote attacker to execute arbitrary code via the sear... |
| CVE-2024-37768 | CRITICAL | 9.1 | 0.6% | Jul 5, 2024 | 14Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id. |
| CVE-2024-29319 | CRITICAL | 9.8 | 0.4% | Jul 5, 2024 | Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. ... |
| CVE-2024-23998 | CRITICAL | 9.6 | 0.7% | Jul 5, 2024 | goanother Another Redis Desktop Manager =<1.6.1 is vulnerable to Cross Site Scripting (XSS) via src/components/Setting.v... |
| CVE-2024-23997 | CRITICAL | 9.6 | 0.7% | Jul 5, 2024 | Lukas Bach yana =<1.0.16 is vulnerable to Cross Site Scripting (XSS) via src/electron-main.ts. |
| CVE-2024-39864 | CRITICAL | 9.8 | 1.8% | Jul 5, 2024 | The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configur... |
| CVE-2024-39028 | CRITICAL | 9.8 | 1.1% | Jul 5, 2024 | An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php. |
| CVE-2024-38346 | CRITICAL | 9.8 | 3.3% | Jul 5, 2024 | The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands... |
| CVE-2024-6298 | CRITICAL | 9.8 | 19.0% | Jul 5, 2024 | Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series ... |
| CVE-2024-39932 | CRITICAL | 9.9 | 17.2% | Jul 4, 2024 | Gogs through 0.13.0 allows argument injection during the previewing of changes. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now