2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2472 | CRITICAL | 9.1 | 0.6% | Jun 14, 2024 | The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a... |
| CVE-2024-5577 | CRITICAL | 9.8 | 0.9% | Jun 14, 2024 | The Where I Was, Where I Will Be plugin for WordPress is vulnerable to Remote File Inclusion in version <= 1.1.1 via the... |
| CVE-2024-4404 | CRITICAL | 9.6 | 0.3% | Jun 14, 2024 | The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, ... |
| CVE-2024-4936 | CRITICAL | 9.8 | 1.0% | Jun 14, 2024 | The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via th... |
| CVE-2024-27174 | CRITICAL | 9.8 | 1.6% | Jun 14, 2024 | Remote Command program allows an attacker to get Remote Code Execution. This vulnerability can be executed in combinatio... |
| CVE-2024-27173 | CRITICAL | 9.8 | 3.2% | Jun 14, 2024 | Remote Command program allows an attacker to get Remote Code Execution by overwriting existing Python files containing e... |
| CVE-2024-27172 | CRITICAL | 9.8 | 26.8% | Jun 14, 2024 | Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, se... |
| CVE-2024-3080 | CRITICAL | 9.8 | 41.6% | Jun 14, 2024 | Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in... |
| CVE-2024-27145 | CRITICAL | 9.8 | 1.0% | Jun 14, 2024 | The Toshiba printers provide several ways to upload files using the admin web interface. An attacker can remotely compro... |
| CVE-2024-27144 | CRITICAL | 9.8 | 1.2% | Jun 14, 2024 | The Toshiba printers provide several ways to upload files using the web interface without authentication. An attacker ca... |
| CVE-2024-27143 | CRITICAL | 9.8 | 1.1% | Jun 14, 2024 | Toshiba printers use SNMP for configuration. Using the private community, it is possible to remotely execute commands as... |
| CVE-2024-5984 | CRITICAL | 9.8 | 0.8% | Jun 14, 2024 | A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. Affected by this issue is... |
| CVE-2024-5983 | CRITICAL | 9.8 | 0.6% | Jun 14, 2024 | A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been declared as critical. Affected by this vulne... |
| CVE-2024-5981 | CRITICAL | 9.8 | 0.5% | Jun 14, 2024 | A vulnerability was found in itsourcecode Online House Rental System 1.0. It has been classified as critical. Affected i... |
| CVE-2024-31777 | CRITICAL | 9.8 | 3.8% | Jun 13, 2024 | File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted fil... |
| CVE-2024-5976 | CRITICAL | 9.8 | 0.7% | Jun 13, 2024 | A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been classified as... |
| CVE-2024-32913 | CRITICAL | 9.8 | 0.3% | Jun 13, 2024 | In wl_notify_rx_mgmt_frame of wl_cfg80211.c, there is a possible out of bounds write due to an integer overflow. This co... |
| CVE-2024-32911 | CRITICAL | 9.8 | 0.2% | Jun 13, 2024 | There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privi... |
| CVE-2024-32905 | CRITICAL | 9.8 | 0.3% | Jun 13, 2024 | In circ_read of link_device_memory_legacy.c, there is a possible out of bounds write due to an incorrect bounds check. T... |
| CVE-2024-29786 | CRITICAL | 9.8 | 0.3% | Jun 13, 2024 | In pktproc_fill_data_addr_without_bm of link_rx_pktproc.c, there is a possible out of bounds write due to a missing boun... |
| CVE-2024-37635 | CRITICAL | 9.8 | 0.7% | Jun 13, 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCf... |
| CVE-2024-37634 | CRITICAL | 9.8 | 0.7% | Jun 13, 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg... |
| CVE-2024-37632 | CRITICAL | 9.8 | 0.6% | Jun 13, 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the password parameter in function ... |
| CVE-2024-38281 | CRITICAL | 9.8 | 0.4% | Jun 13, 2024 | An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device. |
| CVE-2024-22441 | CRITICAL | 9.8 | 0.5% | Jun 13, 2024 | HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now