2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34405 | CRITICAL | 9.1 | 0.5% | Jun 11, 2024 | Improper deep link validation in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to laun... |
| CVE-2024-30080 | CRITICAL | 9.8 | 43.1% | Jun 11, 2024 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2024-2013 | CRITICAL | 10 | 0.7% | Jun 11, 2024 | An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited all... |
| CVE-2024-2012 | CRITICAL | 9.8 | 0.6% | Jun 11, 2024 | vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow uninten... |
| CVE-2024-2011 | CRITICAL | 9.8 | 0.5% | Jun 11, 2024 | A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denia... |
| CVE-2024-5701 | CRITICAL | 9.8 | 0.6% | Jun 11, 2024 | Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2024-5699 | CRITICAL | 9.8 | 0.8% | Jun 11, 2024 | In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by ... |
| CVE-2024-5695 | CRITICAL | 9.8 | 0.6% | Jun 11, 2024 | If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an asserti... |
| CVE-2024-3549 | CRITICAL | 9.9 | 0.5% | Jun 11, 2024 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSort... |
| CVE-2024-36360 | CRITICAL | 9.8 | 1.6% | Jun 11, 2024 | OS command injection vulnerability exists in awkblog v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and e... |
| CVE-2024-31401 | CRITICAL | 9 | 0.5% | Jun 11, 2024 | Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an admin... |
| CVE-2024-29855 | CRITICAL | 9 | 21.6% | Jun 11, 2024 | Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator |
| CVE-2024-37014 | CRITICAL | 9.8 | 0.9% | Jun 10, 2024 | Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_compo... |
| CVE-2024-36417 | CRITICAL | 9 | 0.4% | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6... |
| CVE-2024-36412 | CRITICAL | 9.8 | 5.7% | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6... |
| CVE-2024-32167 | CRITICAL | 9.1 | 0.7% | Jun 10, 2024 | Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend... |
| CVE-2024-5597 | CRITICAL | 9.8 | 0.5% | Jun 10, 2024 | Fuji Electric Monitouch V-SFT is vulnerable to a type confusion, which could cause a crash or code execution. |
| CVE-2024-35746 | CRITICAL | 9.8 | 0.5% | Jun 10, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Asghar Hatampoor BuddyPress Cover allows Code Injection... |
| CVE-2024-31611 | CRITICAL | 9.1 | 0.6% | Jun 10, 2024 | SeaCMS 12.9 has a file deletion vulnerability via admin_template.php. |
| CVE-2024-35677 | CRITICAL | 9.8 | 0.5% | Jun 10, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes MegaMenu ... |
| CVE-2024-35658 | CRITICAL | 9.1 | 0.6% | Jun 10, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeHigh Checkout Field... |
| CVE-2024-34762 | CRITICAL | 9.9 | 0.6% | Jun 10, 2024 | Vulnerability discovered by executing a planned security audit. Improper Limitation of a Pathname to a Restricted Direc... |
| CVE-2024-35307 | CRITICAL | 9.8 | 0.9% | Jun 10, 2024 | Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to e... |
| CVE-2024-35306 | CRITICAL | 9.8 | 0.9% | Jun 10, 2024 | OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This... |
| CVE-2024-35305 | CRITICAL | 9.8 | 0.4% | Jun 10, 2024 | Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora F... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now