2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39931 | CRITICAL | 9.9 | 50.7% | Jul 4, 2024 | Gogs through 0.13.0 allows deletion of internal files. |
| CVE-2024-39930 | CRITICAL | 9.9 | 7.3% | Jul 4, 2024 | The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code ... |
| CVE-2024-39165 | CRITICAL | 9.8 | 0.8% | Jul 4, 2024 | QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary cod... |
| CVE-2024-39844 | CRITICAL | 9.8 | 3.9% | Jul 3, 2024 | In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK. |
| CVE-2024-39223 | CRITICAL | 9.8 | 0.7% | Jul 3, 2024 | An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the... |
| CVE-2024-32937 | CRITICAL | 9.8 | 26.3% | Jul 3, 2024 | An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.... |
| CVE-2024-37082 | CRITICAL | 9.1 | 0.5% | Jul 3, 2024 | When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be po... |
| CVE-2024-4708 | CRITICAL | 9.8 | 1.0% | Jul 2, 2024 | mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device... |
| CVE-2024-38537 | CRITICAL | 9.8 | 1.4% | Jul 2, 2024 | Fides is an open-source privacy engineering platform. `fides.js`, a client-side script used to interact with the consent... |
| CVE-2024-36404 | CRITICAL | 9.8 | 74.9% | Jul 2, 2024 | GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6,... |
| CVE-2024-32755 | CRITICAL | 9.1 | 0.5% | Jul 2, 2024 | Under certain circumstances the web interface will accept characters unrelated to the expected input. |
| CVE-2024-6440 | CRITICAL | 9.8 | 0.5% | Jul 2, 2024 | A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0. It has been classified as crit... |
| CVE-2024-6439 | CRITICAL | 9.8 | 0.7% | Jul 2, 2024 | A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0 and classified as critical. Thi... |
| CVE-2024-37185 | CRITICAL | 9.8 | 0.6% | Jul 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through ... |
| CVE-2024-37077 | CRITICAL | 9.8 | 0.6% | Jul 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through ... |
| CVE-2024-37030 | CRITICAL | 9.8 | 0.6% | Jul 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through ... |
| CVE-2024-36260 | CRITICAL | 9.8 | 0.6% | Jul 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through ... |
| CVE-2024-36243 | CRITICAL | 9.8 | 0.6% | Jul 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through ... |
| CVE-2024-6172 | CRITICAL | 9.8 | 1.1% | Jul 2, 2024 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f... |
| CVE-2024-39309 | CRITICAL | 9.8 | 20.2% | Jul 1, 2024 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability ... |
| CVE-2024-37762 | CRITICAL | 9.9 | 1.5% | Jul 1, 2024 | MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code executio... |
| CVE-2024-5322 | CRITICAL | 9.1 | 0.4% | Jul 1, 2024 | The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can l... |
| CVE-2024-39305 | CRITICAL | 9.1 | 0.6% | Jul 1, 2024 | Envoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy... |
| CVE-2024-38368 | CRITICAL | 9.3 | 14.7% | Jul 1, 2024 | trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older p... |
| CVE-2024-38367 | CRITICAL | 9.6 | 11.0% | Jul 1, 2024 | trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. Prior to commit d4fa66f49cedab44... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now