2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3495 | CRITICAL | 9.8 | 13.6% | May 22, 2024 | The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' paramete... |
| CVE-2024-5147 | CRITICAL | 9.8 | 1.0% | May 22, 2024 | The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Local File Inclusion in all v... |
| CVE-2024-31989 | CRITICAL | 9 | 1.5% | May 21, 2024 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It has been discovered that an unprivileged po... |
| CVE-2024-35056 | CRITICAL | 9.8 | 0.6% | May 21, 2024 | NASA AIT-Core v2.5.2 was discovered to contain multiple SQL injection vulnerabilities via the query_packets and insert f... |
| CVE-2024-35361 | CRITICAL | 9.8 | 0.5% | May 21, 2024 | MTab Bookmark v1.9.5 has an SQL injection vulnerability in /LinkStore/getIcon. An attacker can execute arbitrary SQL sta... |
| CVE-2024-4442 | CRITICAL | 9.1 | 1.2% | May 21, 2024 | The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and includ... |
| CVE-2024-4985 | CRITICAL | 9.8 | 2.6% | May 20, 2024 | An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sig... |
| CVE-2024-35580 | CRITICAL | 9.8 | 0.6% | May 20, 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv. |
| CVE-2024-35571 | CRITICAL | 9.8 | 0.6% | May 20, 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv. |
| CVE-2024-34947 | CRITICAL | 9.4 | 0.4% | May 20, 2024 | Quanxun Huiju Network Technology (Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 was discovered to be vulnerable... |
| CVE-2024-24294 | CRITICAL | 9.8 | 0.8% | May 20, 2024 | A Prototype Pollution issue in Blackprint @blackprint/engine v.0.9.0 allows an attacker to execute arbitrary code via th... |
| CVE-2024-4323 | CRITICAL | 9.8 | 28.3% | May 20, 2024 | A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s... |
| CVE-2024-35960 | CRITICAL | 9.1 | 1.4% | May 20, 2024 | In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Properly link new fs rules into the tree ... |
| CVE-2024-5135 | CRITICAL | 9.8 | 0.7% | May 20, 2024 | A vulnerability was found in PHPGurukul Directory Management System 1.0. It has been rated as critical. This issue affec... |
| CVE-2024-5134 | CRITICAL | 9.8 | 0.6% | May 20, 2024 | A vulnerability was found in SourceCodester Electricity Consumption Monitoring Tool 1.0. It has been declared as critica... |
| CVE-2024-5122 | CRITICAL | 9.8 | 0.7% | May 20, 2024 | A vulnerability was found in SourceCodester Event Registration System 1.0. It has been rated as critical. Affected by th... |
| CVE-2024-5120 | CRITICAL | 9.8 | 0.6% | May 20, 2024 | A vulnerability was found in SourceCodester Event Registration System 1.0. It has been classified as critical. Affected ... |
| CVE-2024-5119 | CRITICAL | 9.8 | 0.6% | May 20, 2024 | A vulnerability was found in SourceCodester Event Registration System 1.0 and classified as critical. This issue affects... |
| CVE-2024-5118 | CRITICAL | 9.8 | 0.7% | May 20, 2024 | A vulnerability has been found in SourceCodester Event Registration System 1.0 and classified as critical. This vulnerab... |
| CVE-2024-5117 | CRITICAL | 9.8 | 0.7% | May 20, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. This affec... |
| CVE-2024-5116 | CRITICAL | 9.8 | 0.8% | May 20, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Online Examination System 1.0. Affec... |
| CVE-2024-36081 | CRITICAL | 9.8 | 0.6% | May 19, 2024 | Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a ... |
| CVE-2024-36080 | CRITICAL | 9.8 | 0.6% | May 19, 2024 | Westermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be cha... |
| CVE-2024-36053 | CRITICAL | 9 | 1.0% | May 19, 2024 | In the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell me... |
| CVE-2024-35870 | CRITICAL | 9.8 | 0.2% | May 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF in smb2_reconnect_server() Th... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now