2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38512 | HIGH | 7.2 | 1.0% | Jul 26, 2024 | A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated priv... |
| CVE-2024-38511 | HIGH | 7.2 | 1.0% | Jul 26, 2024 | A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an aut... |
| CVE-2024-38510 | HIGH | 7.2 | 1.1% | Jul 26, 2024 | A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authe... |
| CVE-2024-38509 | HIGH | 7.2 | 0.5% | Jul 26, 2024 | A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated priv... |
| CVE-2024-38508 | HIGH | 7.2 | 1.0% | Jul 26, 2024 | A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC t... |
| CVE-2024-39304 | HIGH | 8.8 | 3.0% | Jul 26, 2024 | ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an au... |
| CVE-2024-38872 | HIGH | 8.8 | 3.1% | Jul 26, 2024 | Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection i... |
| CVE-2024-38871 | HIGH | 8.8 | 3.1% | Jul 26, 2024 | Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection i... |
| CVE-2024-41813 | HIGH | 7.5 | 0.7% | Jul 26, 2024 | txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Starting ... |
| CVE-2024-41812 | HIGH | 7.5 | 0.7% | Jul 26, 2024 | txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Prior to ... |
| CVE-2024-41354 | HIGH | 7.1 | 0.3% | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php |
| CVE-2024-41353 | HIGH | 7.1 | 0.3% | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php |
| CVE-2024-24257 | HIGH | 7.5 | 0.4% | Jul 26, 2024 | An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sen... |
| CVE-2024-7050 | HIGH | 8.3 | 0.6% | Jul 26, 2024 | Improper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypa... |
| CVE-2024-41357 | HIGH | 7.1 | 1.1% | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php. |
| CVE-2024-41670 | HIGH | 7.5 | 0.4% | Jul 26, 2024 | In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior ... |
| CVE-2024-41692 | HIGH | 8.6 | 0.3% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial inte... |
| CVE-2024-7062 | HIGH | 7.8 | 0.2% | Jul 26, 2024 | Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.Privileged... |
| CVE-2024-41687 | HIGH | 7.5 | 0.3% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote ... |
| CVE-2024-41685 | HIGH | 7.5 | 0.5% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies ass... |
| CVE-2024-35296 | HIGH | 8.2 | 1.1% | Jul 26, 2024 | Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This... |
| CVE-2024-35161 | HIGH | 7.5 | 1.0% | Jul 26, 2024 | Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for reques... |
| CVE-2024-7119 | HIGH | 8.8 | 0.6% | Jul 26, 2024 | A vulnerability, which was classified as critical, has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System u... |
| CVE-2024-7118 | HIGH | 8.8 | 0.5% | Jul 26, 2024 | A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Af... |
| CVE-2024-7117 | HIGH | 8.8 | 0.6% | Jul 26, 2024 | A vulnerability classified as critical has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 2023091... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now