2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5635 | CRITICAL | 9.8 | 0.7% | Jun 4, 2024 | A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been declared as critical. Affected ... |
| CVE-2024-36675 | CRITICAL | 9.1 | 1.4% | Jun 4, 2024 | LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function. |
| CVE-2024-36121 | CRITICAL | 9.1 | 0.3% | Jun 4, 2024 | netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP r... |
| CVE-2024-4219 | CRITICAL | 9.1 | 0.2% | Jun 4, 2024 | Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, ... |
| CVE-2024-28103 | CRITICAL | 9.8 | 0.7% | Jun 4, 2024 | Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permis... |
| CVE-2024-37273 | CRITICAL | 9.8 | 1.0% | Jun 4, 2024 | An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execut... |
| CVE-2024-36858 | CRITICAL | 9.8 | 3.1% | Jun 4, 2024 | An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute... |
| CVE-2024-36604 | CRITICAL | 9.8 | 2.0% | Jun 4, 2024 | Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp functio... |
| CVE-2024-35672 | CRITICAL | 9.8 | 0.5% | Jun 4, 2024 | Missing Authorization vulnerability in Netgsm.This issue affects Netgsm: from n/a through 2.9.19. |
| CVE-2024-35670 | CRITICAL | 9.8 | 0.4% | Jun 4, 2024 | Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/... |
| CVE-2024-36400 | CRITICAL | 9.8 | 0.8% | Jun 4, 2024 | nano-id is a unique string ID generator for Rust. Affected versions of the nano-id crate incorrectly generated IDs using... |
| CVE-2024-35700 | CRITICAL | 9.8 | 0.5% | Jun 4, 2024 | Incorrect Privilege Assignment vulnerability in DeluxeThemes Userpro userpro.This issue affects Userpro: from n/a throug... |
| CVE-2024-35629 | CRITICAL | 9.8 | 0.5% | Jun 4, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-34551 | CRITICAL | 9.8 | 0.5% | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm ... |
| CVE-2024-33560 | CRITICAL | 9 | 0.6% | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore allows PHP... |
| CVE-2024-25600 | CRITICAL | 10 | 87.5% | Jun 4, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Inj... |
| CVE-2024-4253 | CRITICAL | 9.1 | 1.7% | Jun 4, 2024 | A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.y... |
| CVE-2024-36104 | CRITICAL | 9.1 | 87.9% | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue... |
| CVE-2024-4180 | CRITICAL | 9.1 | 1.8% | Jun 4, 2024 | The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering som... |
| CVE-2024-4552 | CRITICAL | 9.8 | 0.6% | Jun 4, 2024 | The Social Login Lite For WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and... |
| CVE-2024-29974 | CRITICAL | 9.8 | 22.8% | Jun 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NA... |
| CVE-2024-29973 | CRITICAL | 9.8 | 86.2% | Jun 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar... |
| CVE-2024-29972 | CRITICAL | 9.8 | 89.2% | Jun 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326... |
| CVE-2024-36782 | CRITICAL | 9.8 | 0.4% | Jun 3, 2024 | TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, whic... |
| CVE-2024-36783 | CRITICAL | 9.8 | 1.4% | Jun 3, 2024 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the N... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now