2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37080 | CRITICAL | 9.8 | 12.5% | Jun 18, 2024 | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor wi... |
| CVE-2024-37079 | CRITICAL | 9.8 | 22.4% | Jun 18, 2024 | vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor wi... |
| CVE-2024-6084 | CRITICAL | 9.8 | 0.9% | Jun 18, 2024 | A vulnerability has been found in itsourcecode Pool of Bethesda Online Reservation System up to 1.0 and classified as cr... |
| CVE-2024-6083 | CRITICAL | 9.8 | 0.5% | Jun 18, 2024 | A vulnerability, which was classified as critical, was found in PHPVibe 11.0.46. Affected is an unknown function of the ... |
| CVE-2024-6067 | CRITICAL | 9.8 | 0.5% | Jun 17, 2024 | A vulnerability classified as critical was found in SourceCodester Music Class Enrollment System 1.0. Affected by this v... |
| CVE-2024-6066 | CRITICAL | 9.8 | 0.5% | Jun 17, 2024 | A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affecte... |
| CVE-2024-6065 | CRITICAL | 9.8 | 0.6% | Jun 17, 2024 | A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been rated as critical. This issue a... |
| CVE-2024-34833 | CRITICAL | 9.8 | 1.9% | Jun 17, 2024 | Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settin... |
| CVE-2024-37902 | CRITICAL | 10 | 0.7% | Jun 17, 2024 | DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Framework in Java. DJL versions 0.1.0 through 0.27.0 do not pre... |
| CVE-2024-36543 | CRITICAL | 9.8 | 0.5% | Jun 17, 2024 | Incorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to d... |
| CVE-2024-36575 | CRITICAL | 9.8 | 0.6% | Jun 17, 2024 | A Prototype Pollution issue in getsetprop 1.1.0 allows an attacker to execute arbitrary code via global.accessor. |
| CVE-2024-36573 | CRITICAL | 9.8 | 0.7% | Jun 17, 2024 | almela obx before v.0.0.4 has a Prototype Pollution issue which allows arbitrary code execution via the obx/build/index.... |
| CVE-2024-36582 | CRITICAL | 9.8 | 0.6% | Jun 17, 2024 | alexbinary object-deep-assign 1.0.11 is vulnerable to Prototype Pollution via the extend() method of Module.deepAssign (... |
| CVE-2024-36580 | CRITICAL | 9.8 | 0.8% | Jun 17, 2024 | A Prototype Pollution issue in cdr0 sg 1.0.10 allows an attacker to execute arbitrary code. |
| CVE-2024-6057 | CRITICAL | 9.8 | 0.9% | Jun 17, 2024 | Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allo... |
| CVE-2024-6048 | CRITICAL | 9.8 | 0.7% | Jun 17, 2024 | Openfind's MailGates and MailAudit fail to properly filter user input when analyzing email attachments. An unauthenticat... |
| CVE-2024-6047 | CRITICAL | 9.8 | 10.0% | Jun 17, 2024 | Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote ... |
| CVE-2024-5163 | CRITICAL | 9.8 | 0.5% | Jun 17, 2024 | Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account secu... |
| CVE-2024-6043 | CRITICAL | 9.8 | 1.9% | Jun 17, 2024 | A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This af... |
| CVE-2024-6042 | CRITICAL | 9.8 | 0.6% | Jun 17, 2024 | A vulnerability was found in itsourcecode Real Estate Management System 1.0. It has been rated as critical. Affected by ... |
| CVE-2024-34451 | CRITICAL | 9.1 | 0.8% | Jun 16, 2024 | Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X... |
| CVE-2024-38396 | CRITICAL | 9.8 | 1.7% | Jun 16, 2024 | An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in ... |
| CVE-2024-38468 | CRITICAL | 9.8 | 0.4% | Jun 16, 2024 | Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API. |
| CVE-2024-38466 | CRITICAL | 9.8 | 0.4% | Jun 16, 2024 | Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password. |
| CVE-2024-38462 | CRITICAL | 9.8 | 0.6% | Jun 16, 2024 | iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mai... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now