2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35260 | CRITICAL | 9.8 | 1.0% | Jun 27, 2024 | An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over... |
| CVE-2024-39669 | CRITICAL | 9.8 | 0.8% | Jun 27, 2024 | In the Console in Soffid IAM before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent co... |
| CVE-2024-39376 | CRITICAL | 9.8 | 0.5% | Jun 27, 2024 | TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performin... |
| CVE-2024-39375 | CRITICAL | 9.8 | 0.6% | Jun 27, 2024 | TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileg... |
| CVE-2024-39374 | CRITICAL | 9.8 | 0.5% | Jun 27, 2024 | TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed thro... |
| CVE-2024-6373 | CRITICAL | 9.8 | 0.9% | Jun 27, 2024 | A vulnerability has been found in itsourcecode Online Food Ordering System up to 1.0 and classified as critical. This vu... |
| CVE-2024-6372 | CRITICAL | 9.8 | 0.6% | Jun 27, 2024 | A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affec... |
| CVE-2024-6371 | CRITICAL | 9.8 | 0.7% | Jun 27, 2024 | A vulnerability, which was classified as critical, has been found in itsourcecode Pool of Bethesda Online Reservation Sy... |
| CVE-2024-1107 | CRITICAL | 9.8 | 0.5% | Jun 27, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Talya Informatics Travel APPS allows Exploiting Incorr... |
| CVE-2024-5535 | CRITICAL | 9.1 | 5.6% | Jun 27, 2024 | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer ma... |
| CVE-2024-0949 | CRITICAL | 9.8 | 0.5% | Jun 27, 2024 | Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability... |
| CVE-2024-0947 | CRITICAL | 9.8 | 0.5% | Jun 27, 2024 | Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics Elektraweb allows Sessi... |
| CVE-2024-37734 | CRITICAL | 9.8 | 0.8% | Jun 26, 2024 | An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid par... |
| CVE-2024-1839 | CRITICAL | 10 | 0.5% | Jun 26, 2024 | Intrado 911 Emergency Gateway login form is vulnerable to an unauthenticated blind time-based SQL injection, which may a... |
| CVE-2024-39243 | CRITICAL | 9.8 | 0.5% | Jun 26, 2024 | An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/adm... |
| CVE-2024-4228 | CRITICAL | 9.8 | 0.5% | Jun 26, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive ... |
| CVE-2024-37252 | CRITICAL | 9.3 | 0.5% | Jun 26, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subs... |
| CVE-2024-37098 | CRITICAL | 9.8 | 0.3% | Jun 26, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter.This issue affects Blo... |
| CVE-2024-5181 | CRITICAL | 9.8 | 2.7% | Jun 26, 2024 | A command injection vulnerability exists in the mudler/localai version 2.14.0. The vulnerability arises from the applica... |
| CVE-2024-6060 | CRITICAL | 9.3 | 0.2% | Jun 25, 2024 | An information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with access to the log files to ... |
| CVE-2024-35527 | CRITICAL | 9.8 | 0.7% | Jun 25, 2024 | An arbitrary file upload vulnerability in /fileupload/upload.cfm in Daemon PTY Limited FarCry Core framework before 7.2.... |
| CVE-2024-37843 | CRITICAL | 9.8 | 51.3% | Jun 25, 2024 | Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint. |
| CVE-2024-21741 | CRITICAL | 9.8 | 0.4% | Jun 25, 2024 | GigaDevice GD32E103C8T6 devices have Incorrect Access Control. |
| CVE-2024-5276 | CRITICAL | 9.1 | 90.1% | Jun 25, 2024 | A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data. Likely imp... |
| CVE-2024-4885 | CRITICAL | 9.8 | 99.3% | Jun 25, 2024 | In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress Wh... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now