2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42051 | HIGH | 7.8 | 0.2% | Jul 28, 2024 | The MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with weak permissions during... |
| CVE-2024-42050 | HIGH | 7 | 0.1% | Jul 28, 2024 | The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during... |
| CVE-2024-7152 | HIGH | 8.8 | 1.3% | Jul 27, 2024 | A vulnerability was found in Tenda O3 1.0.0.10(2478). It has been rated as critical. This issue affects the function fro... |
| CVE-2024-6431 | HIGH | 8.8 | 0.8% | Jul 27, 2024 | The Media.net Ads Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati... |
| CVE-2024-6152 | HIGH | 8.8 | 0.6% | Jul 27, 2024 | The Flipbox Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5... |
| CVE-2024-40433 | HIGH | 8.8 | 1.2% | Jul 26, 2024 | Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view... |
| CVE-2024-41815 | HIGH | 7 | 0.5% | Jul 26, 2024 | Starship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable ... |
| CVE-2024-41628 | HIGH | 7.5 | 6.5% | Jul 26, 2024 | Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and ... |
| CVE-2024-40116 | HIGH | 8.1 | 0.4% | Jul 26, 2024 | An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the expo... |
| CVE-2024-38512 | HIGH | 7.2 | 1.0% | Jul 26, 2024 | A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated priv... |
| CVE-2024-38511 | HIGH | 7.2 | 1.0% | Jul 26, 2024 | A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an aut... |
| CVE-2024-38510 | HIGH | 7.2 | 1.1% | Jul 26, 2024 | A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authe... |
| CVE-2024-38509 | HIGH | 7.2 | 0.5% | Jul 26, 2024 | A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated priv... |
| CVE-2024-38508 | HIGH | 7.2 | 1.0% | Jul 26, 2024 | A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC t... |
| CVE-2024-39304 | HIGH | 8.8 | 3.0% | Jul 26, 2024 | ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an au... |
| CVE-2024-38872 | HIGH | 8.8 | 3.1% | Jul 26, 2024 | Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection i... |
| CVE-2024-38871 | HIGH | 8.8 | 3.1% | Jul 26, 2024 | Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection i... |
| CVE-2024-41813 | HIGH | 7.5 | 0.7% | Jul 26, 2024 | txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Starting ... |
| CVE-2024-41812 | HIGH | 7.5 | 0.7% | Jul 26, 2024 | txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Prior to ... |
| CVE-2024-41354 | HIGH | 7.1 | 0.3% | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php |
| CVE-2024-41353 | HIGH | 7.1 | 0.3% | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php |
| CVE-2024-24257 | HIGH | 7.5 | 0.4% | Jul 26, 2024 | An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sen... |
| CVE-2024-7050 | HIGH | 8.3 | 0.6% | Jul 26, 2024 | Improper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypa... |
| CVE-2024-41357 | HIGH | 7.1 | 1.1% | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php. |
| CVE-2024-41670 | HIGH | 7.5 | 0.4% | Jul 26, 2024 | In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now