2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39672 | HIGH | 7.1 | 0.1% | Jul 25, 2024 | Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affe... |
| CVE-2024-6589 | HIGH | 8.8 | 0.8% | Jul 25, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, ... |
| CVE-2024-37084 | HIGH | 8.8 | 35.2% | Jul 25, 2024 | In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a... |
| CVE-2024-41466 | HIGH | 7.5 | 0.6% | Jul 24, 2024 | Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at i... |
| CVE-2024-41465 | HIGH | 7.5 | 0.6% | Jul 24, 2024 | Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter... |
| CVE-2024-41464 | HIGH | 7.5 | 0.6% | Jul 24, 2024 | Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parame... |
| CVE-2024-41463 | HIGH | 7.5 | 0.5% | Jul 24, 2024 | Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at... |
| CVE-2024-41462 | HIGH | 7.5 | 0.6% | Jul 24, 2024 | Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at i... |
| CVE-2024-41136 | HIGH | 8.8 | 0.9% | Jul 24, 2024 | An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command ... |
| CVE-2024-7080 | HIGH | 7.5 | 1.0% | Jul 24, 2024 | A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been declared as problematic. Affect... |
| CVE-2024-41550 | HIGH | 7.2 | 0.5% | Jul 24, 2024 | CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_invoice... |
| CVE-2024-41135 | HIGH | 7.2 | 0.8% | Jul 24, 2024 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot... |
| CVE-2024-41134 | HIGH | 7.2 | 0.7% | Jul 24, 2024 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot... |
| CVE-2024-41133 | HIGH | 7.2 | 0.8% | Jul 24, 2024 | A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot... |
| CVE-2024-36534 | HIGH | 8.4 | 0.2% | Jul 24, 2024 | Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtainin... |
| CVE-2024-33519 | HIGH | 7.2 | 0.7% | Jul 24, 2024 | A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an ... |
| CVE-2024-40495 | HIGH | 8 | 0.9% | Jul 24, 2024 | A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute a... |
| CVE-2024-36538 | HIGH | 8.8 | 0.6% | Jul 24, 2024 | Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining... |
| CVE-2024-36537 | HIGH | 7.2 | 0.4% | Jul 24, 2024 | Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtain... |
| CVE-2024-41672 | HIGH | 7.5 | 0.8% | Jul 24, 2024 | DuckDB is a SQL database management system. In versions 1.0.0 and prior, content in filesystem is accessible for reading... |
| CVE-2024-41667 | HIGH | 8.8 | 3.5% | Jul 24, 2024 | OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in Re... |
| CVE-2024-7069 | HIGH | 7.5 | 0.4% | Jul 24, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Loggi... |
| CVE-2024-36541 | HIGH | 8.8 | 0.4% | Jul 24, 2024 | Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obt... |
| CVE-2024-31970 | HIGH | 8.8 | 0.6% | Jul 24, 2024 | AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have SSH enabled by default... |
| CVE-2024-39345 | HIGH | 7.2 | 0.5% | Jul 24, 2024 | AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented,... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now