2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38441 | CRITICAL | 9.8 | 0.9% | Jun 16, 2024 | Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '... |
| CVE-2024-38439 | CRITICAL | 9.8 | 0.9% | Jun 16, 2024 | Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN... |
| CVE-2024-38428 | CRITICAL | 9.1 | 0.7% | Jun 16, 2024 | url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be inse... |
| CVE-2024-38395 | CRITICAL | 9.8 | 1.5% | Jun 16, 2024 | In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution mi... |
| CVE-2024-6016 | CRITICAL | 9.8 | 0.5% | Jun 15, 2024 | A vulnerability, which was classified as critical, has been found in itsourcecode Online Laundry Management System 1.0. ... |
| CVE-2024-6015 | CRITICAL | 9.8 | 0.5% | Jun 15, 2024 | A vulnerability classified as critical was found in itsourcecode Online House Rental System 1.0. Affected by this vulner... |
| CVE-2024-6014 | CRITICAL | 9.8 | 0.5% | Jun 15, 2024 | A vulnerability classified as critical has been found in itsourcecode Document Management System 1.0. Affected is an unk... |
| CVE-2024-6013 | CRITICAL | 9.8 | 0.5% | Jun 15, 2024 | A vulnerability was found in itsourcecode Online Book Store 1.0. It has been rated as critical. This issue affects some ... |
| CVE-2024-6009 | CRITICAL | 9.8 | 0.5% | Jun 15, 2024 | A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerabi... |
| CVE-2024-6007 | CRITICAL | 9.8 | 0.6% | Jun 15, 2024 | A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects... |
| CVE-2024-4258 | CRITICAL | 9.8 | 0.8% | Jun 15, 2024 | The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusi... |
| CVE-2024-3105 | CRITICAL | 9.9 | 2.8% | Jun 15, 2024 | The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execu... |
| CVE-2024-5871 | CRITICAL | 9.8 | 0.7% | Jun 15, 2024 | The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc... |
| CVE-2024-37831 | CRITICAL | 9.8 | 0.4% | Jun 14, 2024 | Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter. |
| CVE-2024-37642 | CRITICAL | 9.1 | 11.4% | Jun 14, 2024 | TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_p... |
| CVE-2024-34539 | CRITICAL | 9.4 | 0.5% | Jun 14, 2024 | Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail ... |
| CVE-2024-33375 | CRITICAL | 9.8 | 0.6% | Jun 14, 2024 | LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware. |
| CVE-2024-33374 | CRITICAL | 9.8 | 0.5% | Jun 14, 2024 | Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access th... |
| CVE-2024-5671 | CRITICAL | 9.8 | 0.9% | Jun 14, 2024 | Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitra... |
| CVE-2024-37637 | CRITICAL | 9.8 | 0.7% | Jun 14, 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWizardCfg... |
| CVE-2024-3912 | CRITICAL | 9.8 | 1.0% | Jun 14, 2024 | Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can e... |
| CVE-2024-2472 | CRITICAL | 9.1 | 0.6% | Jun 14, 2024 | The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a... |
| CVE-2024-5577 | CRITICAL | 9.8 | 0.9% | Jun 14, 2024 | The Where I Was, Where I Will Be plugin for WordPress is vulnerable to Remote File Inclusion in version <= 1.1.1 via the... |
| CVE-2024-4404 | CRITICAL | 9.6 | 0.3% | Jun 14, 2024 | The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, ... |
| CVE-2024-4936 | CRITICAL | 9.8 | 1.0% | Jun 14, 2024 | The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via th... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now