2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3740 | CRITICAL | 9.8 | 0.8% | Apr 13, 2024 | A vulnerability, which was classified as critical, has been found in cym1102 nginxWebUI up to 3.9.9. This issue affects ... |
| CVE-2024-3739 | CRITICAL | 9.8 | 2.9% | Apr 13, 2024 | A vulnerability classified as critical was found in cym1102 nginxWebUI up to 3.9.9. This vulnerability affects unknown c... |
| CVE-2024-3738 | CRITICAL | 9.8 | 0.5% | Apr 13, 2024 | A vulnerability classified as critical has been found in cym1102 nginxWebUI up to 3.9.9. This affects the function handl... |
| CVE-2024-3737 | CRITICAL | 9.8 | 0.9% | Apr 13, 2024 | A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been rated as critical. Affected by this issue is th... |
| CVE-2024-3691 | CRITICAL | 9.8 | 0.9% | Apr 12, 2024 | A vulnerability, which was classified as critical, has been found in PHPGurukul Small CRM 3.0. Affected by this issue is... |
| CVE-2024-28878 | CRITICAL | 9.6 | 0.3% | Apr 12, 2024 | IO-1020 Micro ELD downloads source code or an executable from an adjacent location and executes the code without suffi... |
| CVE-2024-30407 | CRITICAL | 9.2 | 0.7% | Apr 12, 2024 | The Use of a Hard-coded Cryptographic Key vulnerability in Juniper Networks Juniper Cloud Native Router (JCNR) and conta... |
| CVE-2024-3704 | CRITICAL | 9.8 | 0.7% | Apr 12, 2024 | SQL Injection Vulnerability has been found on OpenGnsys product affecting version 1.1.1d (Espeto). This vulnerability al... |
| CVE-2024-3685 | CRITICAL | 9.8 | 0.6% | Apr 12, 2024 | A vulnerability, which was classified as critical, was found in DedeCMS 5.7.112-UTF8. Affected is an unknown function of... |
| CVE-2024-31818 | CRITICAL | 9.8 | 1.9% | Apr 12, 2024 | Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page para... |
| CVE-2024-28718 | CRITICAL | 9.8 | 1.1% | Apr 12, 2024 | An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py... |
| CVE-2024-3400 | CRITICAL | 10 | 100.0% | Apr 12, 2024 | A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Netwo... |
| CVE-2024-22718 | CRITICAL | 9.6 | 0.7% | Apr 11, 2024 | Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id pa... |
| CVE-2024-31678 | CRITICAL | 9.8 | 0.6% | Apr 11, 2024 | Sourcecodester Loan Management System v1.0 is vulnerable to SQL Injection via the "password" parameter in the "login.php... |
| CVE-2024-21508 | CRITICAL | 9.8 | 2.6% | Apr 11, 2024 | Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function d... |
| CVE-2024-29937 | CRITICAL | 9.8 | 1.8% | Apr 11, 2024 | NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers ... |
| CVE-2024-27683 | CRITICAL | 9.8 | 0.9% | Apr 11, 2024 | D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function hnap_main. An attacke... |
| CVE-2024-25935 | CRITICAL | 9.8 | 0.4% | Apr 11, 2024 | Missing Authorization vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a throug... |
| CVE-2024-25912 | CRITICAL | 9.8 | 0.6% | Apr 11, 2024 | Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2. |
| CVE-2024-31996 | CRITICAL | 9.8 | 2.1% | Apr 10, 2024 | XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc... |
| CVE-2024-31982 | CRITICAL | 9.8 | 34.5% | Apr 10, 2024 | XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, an... |
| CVE-2024-31819 | CRITICAL | 9.8 | 15.6% | Apr 10, 2024 | An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath ... |
| CVE-2024-29500 | CRITICAL | 9.8 | 1.0% | Apr 10, 2024 | An issue in the kiosk mode of Secure Lockdown Multi Application Edition v2.00.219 allows attackers to execute arbitrary ... |
| CVE-2024-3157 | CRITICAL | 9.6 | 0.8% | Apr 10, 2024 | Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had co... |
| CVE-2024-31461 | CRITICAL | 9.1 | 0.7% | Apr 10, 2024 | Plane, an open-source project management tool, has a Server-Side Request Forgery (SSRF) vulnerability in versions prior ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now