2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4884 | CRITICAL | 9.8 | 24.3% | Jun 25, 2024 | In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress Wh... |
| CVE-2024-4883 | CRITICAL | 9.8 | 64.8% | Jun 25, 2024 | In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This v... |
| CVE-2024-6308 | CRITICAL | 9.8 | 0.7% | Jun 25, 2024 | A vulnerability was found in itsourcecode Simple Online Hotel Reservation System 1.0. It has been declared as critical. ... |
| CVE-2024-5989 | CRITICAL | 9.8 | 2.4% | Jun 25, 2024 | Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injectio... |
| CVE-2024-5988 | CRITICAL | 9.8 | 2.7% | Jun 25, 2024 | Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or r... |
| CVE-2024-5806 | CRITICAL | 9.8 | 75.8% | Jun 25, 2024 | Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This i... |
| CVE-2024-5805 | CRITICAL | 9.1 | 7.6% | Jun 25, 2024 | Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue ... |
| CVE-2024-39462 | CRITICAL | 9.8 | 0.8% | Jun 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: clk: bcm: dvp: Assign ->num before accessing ->hws ... |
| CVE-2024-5261 | CRITICAL | 9.8 | 0.4% | Jun 25, 2024 | Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verificati... |
| CVE-2024-4641 | CRITICAL | 9.8 | 0.3% | Jun 25, 2024 | OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format... |
| CVE-2024-6028 | CRITICAL | 9.8 | 11.8% | Jun 25, 2024 | The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all v... |
| CVE-2024-6297 | CRITICAL | 10 | 1.0% | Jun 25, 2024 | Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A m... |
| CVE-2024-4197 | CRITICAL | 9.8 | 0.8% | Jun 25, 2024 | An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code exec... |
| CVE-2024-4196 | CRITICAL | 9.8 | 0.6% | Jun 25, 2024 | An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code ex... |
| CVE-2024-36681 | CRITICAL | 9.8 | 0.5% | Jun 24, 2024 | SQL Injection vulnerability in the module "Isotope" (pk_isotope) <=1.7.3 from Promokit.eu for PrestaShop allows attacker... |
| CVE-2024-34988 | CRITICAL | 9.8 | 0.4% | Jun 24, 2024 | SQL injection vulnerability in the module "Complete for Create a Quote in Frontend + Backend Pro" (askforaquotemodul) <=... |
| CVE-2024-33898 | CRITICAL | 9.8 | 0.7% | Jun 24, 2024 | Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An ... |
| CVE-2024-38902 | CRITICAL | 9.8 | 0.5% | Jun 24, 2024 | H3C Magic R230 V100R002 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attack... |
| CVE-2024-37759 | CRITICAL | 9.8 | 2.8% | Jun 24, 2024 | DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerabi... |
| CVE-2024-34313 | CRITICAL | 9.8 | 1.5% | Jun 24, 2024 | An issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a pu... |
| CVE-2024-33879 | CRITICAL | 9.8 | 0.6% | Jun 24, 2024 | An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileD... |
| CVE-2024-33278 | CRITICAL | 9.8 | 0.8% | Jun 24, 2024 | Buffer Overflow vulnerability in ASUS router RT-AX88U with firmware versions v3.0.0.4.388_24198 allows a remote attacker... |
| CVE-2024-37231 | CRITICAL | 9.1 | 0.6% | Jun 24, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salon Booking System Sal... |
| CVE-2024-37228 | CRITICAL | 9.8 | 0.5% | Jun 24, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affe... |
| CVE-2024-37089 | CRITICAL | 9.8 | 0.6% | Jun 24, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consultin... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now