2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7080 | HIGH | 7.5 | 1.0% | Jul 24, 2024 | A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been declared as problematic. Affect... |
| CVE-2024-41550 | HIGH | 7.2 | 0.5% | Jul 24, 2024 | CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_invoice... |
| CVE-2024-41135 | HIGH | 7.2 | 0.8% | Jul 24, 2024 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot... |
| CVE-2024-41134 | HIGH | 7.2 | 0.7% | Jul 24, 2024 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot... |
| CVE-2024-41133 | HIGH | 7.2 | 0.8% | Jul 24, 2024 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot... |
| CVE-2024-36534 | HIGH | 8.4 | 0.2% | Jul 24, 2024 | Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtainin... |
| CVE-2024-33519 | HIGH | 7.2 | 0.7% | Jul 24, 2024 | A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an ... |
| CVE-2024-40495 | HIGH | 8 | 0.9% | Jul 24, 2024 | A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute a... |
| CVE-2024-36538 | HIGH | 8.8 | 0.6% | Jul 24, 2024 | Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining... |
| CVE-2024-36537 | HIGH | 7.2 | 0.4% | Jul 24, 2024 | Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtain... |
| CVE-2024-41672 | HIGH | 7.5 | 0.8% | Jul 24, 2024 | DuckDB is a SQL database management system. In versions 1.0.0 and prior, content in filesystem is accessible for reading... |
| CVE-2024-41667 | HIGH | 8.8 | 3.5% | Jul 24, 2024 | OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in Re... |
| CVE-2024-7069 | HIGH | 7.5 | 0.4% | Jul 24, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Loggi... |
| CVE-2024-36541 | HIGH | 8.8 | 0.4% | Jul 24, 2024 | Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obt... |
| CVE-2024-31970 | HIGH | 8.8 | 0.6% | Jul 24, 2024 | AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have SSH enabled by default... |
| CVE-2024-39345 | HIGH | 7.2 | 0.5% | Jul 24, 2024 | AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented,... |
| CVE-2024-31977 | HIGH | 8.8 | 1.7% | Jul 24, 2024 | Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via s... |
| CVE-2024-22443 | HIGH | 8.8 | 0.8% | Jul 24, 2024 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re... |
| CVE-2024-7067 | HIGH | 8.8 | 0.8% | Jul 24, 2024 | A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87. It ... |
| CVE-2024-6197 | HIGH | 7.5 | 4.3% | Jul 24, 2024 | libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid fi... |
| CVE-2024-39676 | HIGH | 7.5 | 0.8% | Jul 24, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pin... |
| CVE-2024-7027 | HIGH | 7.3 | 0.4% | Jul 24, 2024 | The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ... |
| CVE-2024-6756 | HIGH | 8.8 | 0.8% | Jul 24, 2024 | The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation ... |
| CVE-2024-6750 | HIGH | 7.5 | 0.3% | Jul 24, 2024 | The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to ... |
| CVE-2024-38176 | HIGH | 8.1 | 0.9% | Jul 23, 2024 | An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate pri... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now