2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-40479 | HIGH | 8.1 | 0.8% | Aug 12, 2024 | A SQL injection vulnerability in "/admin/quizquestion.php" in Kashipara Online Exam System v1.0 allows remote attackers ... |
| CVE-2024-40476 | HIGH | 8 | 0.3% | Aug 12, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. ... |
| CVE-2024-40475 | HIGH | 8.8 | 0.5% | Aug 12, 2024 | SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_re... |
| CVE-2024-39815 | HIGH | 7.5 | 0.8% | Aug 12, 2024 | Improper check or handling of exceptional conditions vulnerability affecting Vonets industrial wifi bridge relays ... |
| CVE-2024-39338 | HIGH | 7.5 | 1.4% | Aug 12, 2024 | axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative... |
| CVE-2024-38218 | HIGH | 7.8 | 0.6% | Aug 12, 2024 | Microsoft Edge (HTML-based) Memory Corruption Vulnerability |
| CVE-2024-37826 | HIGH | 7.5 | 1.2% | Aug 12, 2024 | A NULL pointer dereference in vercot Serva v4.6.0 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP... |
| CVE-2024-36462 | HIGH | 7.5 | 0.9% | Aug 12, 2024 | Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources... |
| CVE-2024-36461 | HIGH | 8.8 | 0.8% | Aug 12, 2024 | Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine. |
| CVE-2024-36460 | HIGH | 8.1 | 0.6% | Aug 12, 2024 | The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain te... |
| CVE-2024-36035 | HIGH | 8.8 | 7.4% | Aug 12, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session rec... |
| CVE-2024-36034 | HIGH | 8.8 | 7.4% | Aug 12, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate report... |
| CVE-2024-30188 | HIGH | 8.1 | 6.0% | Aug 12, 2024 | File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional reso... |
| CVE-2024-29831 | HIGH | 8.8 | 1.2% | Aug 12, 2024 | Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandbox... |
| CVE-2024-29082 | HIGH | 8.6 | 0.8% | Aug 12, 2024 | Improper access control vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, softwa... |
| CVE-2024-22116 | HIGH | 7.2 | 1.6% | Aug 12, 2024 | An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts ... |
| CVE-2024-21881 | HIGH | 8.6 | 0.3% | Aug 12, 2024 | Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encryp... |
| CVE-2024-21880 | HIGH | 7.2 | 2.3% | Aug 12, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter ... |
| CVE-2024-21879 | HIGH | 8.8 | 2.5% | Aug 12, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url paramet... |
| CVE-2024-0113 | HIGH | 8.8 | 1.0% | Aug 12, 2024 | NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cau... |
| CVE-2024-39287 | HIGH | 7.5 | 0.3% | Aug 8, 2024 | Dorsett Controls Central Server update server has potential information leaks with an unprotected file that contains pa... |
| CVE-2024-37382 | HIGH | 7.2 | 0.4% | Aug 8, 2024 | An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows att... |
| CVE-2024-0104 | HIGH | 8.8 | 0.3% | Aug 8, 2024 | NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a us... |
| CVE-2024-42365 | HIGH | 8.8 | 4.7% | Aug 8, 2024 | Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9... |
| CVE-2024-0108 | HIGH | 8.8 | 0.2% | Aug 8, 2024 | NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean u... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now