2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36470 | CRITICAL | 9.8 | 0.5% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific e... |
| CVE-2024-3412 | CRITICAL | 9.1 | 0.8% | May 29, 2024 | The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file u... |
| CVE-2024-3050 | CRITICAL | 9.1 | 0.6% | May 29, 2024 | The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowin... |
| CVE-2024-5150 | CRITICAL | 9.8 | 0.8% | May 29, 2024 | The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including... |
| CVE-2024-35510 | CRITICAL | 9.8 | 0.7% | May 28, 2024 | An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute ... |
| CVE-2024-35563 | CRITICAL | 9.8 | 0.5% | May 28, 2024 | CDG-Server-V5.6.2.126.139 and earlier was discovered to contain a SQL injection vulnerability via the permissionId param... |
| CVE-2024-35344 | CRITICAL | 9.9 | 0.4% | May 28, 2024 | Certain Anpviz products contain a hardcoded cryptographic key stored in the firmware of the device. This affects IPC-D25... |
| CVE-2024-35343 | CRITICAL | 9.8 | 0.5% | May 28, 2024 | Certain Anpviz products allow unauthenticated users to download arbitrary files from the device's filesystem via a HTTP ... |
| CVE-2024-34854 | CRITICAL | 9.8 | 12.8% | May 28, 2024 | F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.` |
| CVE-2024-35324 | CRITICAL | 9.8 | 2.1% | May 28, 2024 | Douchat 4.0.5 suffers from an arbitrary file upload vulnerability via Public/Plugins/webuploader/server/preview.php. |
| CVE-2024-33808 | CRITICAL | 9.8 | 0.5% | May 28, 2024 | A SQL injection vulnerability in /model/get_timetable.php in campcodes Complete Web-Based School Management System 1.0 a... |
| CVE-2024-33806 | CRITICAL | 9.8 | 0.5% | May 28, 2024 | A SQL injection vulnerability in /model/get_grade.php in campcodes Complete Web-Based School Management System 1.0 allow... |
| CVE-2024-33805 | CRITICAL | 9.8 | 0.5% | May 28, 2024 | A SQL injection vulnerability in /model/get_student.php in campcodes Complete Web-Based School Management System 1.0 all... |
| CVE-2024-33801 | CRITICAL | 9.8 | 0.5% | May 28, 2024 | A SQL injection vulnerability in /model/get_subject_routing.php in campcodes Complete Web-Based School Management System... |
| CVE-2024-33800 | CRITICAL | 9.8 | 0.5% | May 28, 2024 | A SQL injection vulnerability in /model/get_student1.php in campcodes Complete Web-Based School Management System 1.0 al... |
| CVE-2024-33799 | CRITICAL | 9.8 | 0.5% | May 28, 2024 | A SQL injection vulnerability in /model/get_teacher.php in campcodes Complete Web-Based School Management System 1.0 all... |
| CVE-2024-24963 | CRITICAL | 9.8 | 1.2% | May 28, 2024 | A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of Au... |
| CVE-2024-24962 | CRITICAL | 9.8 | 1.2% | May 28, 2024 | A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of Au... |
| CVE-2024-23601 | CRITICAL | 9.8 | 0.7% | May 28, 2024 | A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A speciall... |
| CVE-2024-22590 | CRITICAL | 9.1 | 0.6% | May 28, 2024 | The TLS engine in Kwik commit 745fd4e2 does not track the current state of the connection. This vulnerability can allow ... |
| CVE-2024-22187 | CRITICAL | 9.1 | 1.0% | May 28, 2024 | A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality o... |
| CVE-2024-21785 | CRITICAL | 9.8 | 1.5% | May 28, 2024 | A leftover debug code vulnerability exists in the Telnet Diagnostic Interface functionality of AutomationDirect P3-550E ... |
| CVE-2024-5274 | CRITICAL | 9.6 | 10.0% | May 28, 2024 | Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside... |
| CVE-2024-3969 | CRITICAL | 9.8 | 0.5% | May 28, 2024 | XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execu... |
| CVE-2024-35398 | CRITICAL | 9.8 | 0.7% | May 28, 2024 | TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now