2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41692 | HIGH | 8.6 | 0.3% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial inte... |
| CVE-2024-7062 | HIGH | 7.8 | 0.2% | Jul 26, 2024 | Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.Privileged... |
| CVE-2024-41687 | HIGH | 7.5 | 0.3% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote ... |
| CVE-2024-41685 | HIGH | 7.5 | 0.5% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies ass... |
| CVE-2024-35296 | HIGH | 8.2 | 1.1% | Jul 26, 2024 | Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This... |
| CVE-2024-35161 | HIGH | 7.5 | 1.0% | Jul 26, 2024 | Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for reques... |
| CVE-2024-7119 | HIGH | 8.8 | 0.6% | Jul 26, 2024 | A vulnerability, which was classified as critical, has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System u... |
| CVE-2024-7118 | HIGH | 8.8 | 0.5% | Jul 26, 2024 | A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. Af... |
| CVE-2024-7117 | HIGH | 8.8 | 0.6% | Jul 26, 2024 | A vulnerability classified as critical has been found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 2023091... |
| CVE-2024-7116 | HIGH | 8.8 | 0.5% | Jul 26, 2024 | A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been rated as crit... |
| CVE-2024-7115 | HIGH | 8.8 | 0.5% | Jul 26, 2024 | A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It has been declared as c... |
| CVE-2024-7114 | HIGH | 8.8 | 0.6% | Jul 26, 2024 | A vulnerability was found in Tianchoy Blog up to 1.8.8. It has been classified as critical. This affects an unknown part... |
| CVE-2024-24623 | HIGH | 8.8 | 1.9% | Jul 25, 2024 | Softaculous Webuzo contains a command injection vulnerability in the FTP management functionality. A remote, authenticat... |
| CVE-2024-24622 | HIGH | 8.8 | 1.9% | Jul 25, 2024 | Softaculous Webuzo contains a command injection in the password reset functionality. A remote, authenticated attacker ca... |
| CVE-2024-7106 | HIGH | 8.8 | 0.4% | Jul 25, 2024 | A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this vulnerability is an unknown fu... |
| CVE-2024-7105 | HIGH | 8.8 | 0.4% | Jul 25, 2024 | A vulnerability classified as critical has been found in ForIP Tecnologia Administração PABX 1.x. Affected is an unknown... |
| CVE-2024-38288 | HIGH | 7.2 | 3.2% | Jul 25, 2024 | A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allow... |
| CVE-2024-29069 | HIGH | 7.3 | 0.2% | Jul 25, 2024 | In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap... |
| CVE-2024-40318 | HIGH | 7.2 | 1.2% | Jul 25, 2024 | An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploadi... |
| CVE-2024-1724 | HIGH | 8.2 | 0.3% | Jul 25, 2024 | In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict w... |
| CVE-2024-41800 | HIGH | 7.5 | 0.4% | Jul 25, 2024 | Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity p... |
| CVE-2024-40872 | HIGH | 8.4 | 0.2% | Jul 25, 2024 | There is an elevation of privilege vulnerability in server and client components of Absolute Secure Access prior to vers... |
| CVE-2024-36542 | HIGH | 8.8 | 0.5% | Jul 25, 2024 | Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the s... |
| CVE-2024-7101 | HIGH | 7.3 | 0.5% | Jul 25, 2024 | A vulnerability, which was classified as critical, has been found in ForIP Tecnologia Administração PABX 1.x. This issue... |
| CVE-2024-39673 | HIGH | 7.1 | 0.1% | Jul 25, 2024 | Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now