2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34329 | HIGH | 8.4 | 0.6% | Jul 22, 2024 | Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch al... |
| CVE-2024-40634 | HIGH | 7.5 | 1.4% | Jul 22, 2024 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability i... |
| CVE-2024-40051 | HIGH | 7.5 | 0.7% | Jul 22, 2024 | IP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter. |
| CVE-2024-41829 | HIGH | 7.5 | 0.3% | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection |
| CVE-2024-41132 | HIGH | 7.5 | 0.8% | Jul 22, 2024 | ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially... |
| CVE-2024-41131 | HIGH | 7.5 | 0.7% | Jul 22, 2024 | ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allo... |
| CVE-2024-32484 | HIGH | 8.2 | 24.4% | Jul 22, 2024 | An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A sp... |
| CVE-2024-26020 | HIGH | 8.8 | 14.1% | Jul 22, 2024 | An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted... |
| CVE-2024-41320 | HIGH | 8.8 | 2.2% | Jul 22, 2024 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet... |
| CVE-2024-41317 | HIGH | 8 | 2.3% | Jul 22, 2024 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet... |
| CVE-2024-39601 | HIGH | 7.1 | 0.5% | Jul 22, 2024 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base syste... |
| CVE-2024-25638 | HIGH | 8.9 | 0.4% | Jul 22, 2024 | dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, al... |
| CVE-2024-38788 | HIGH | 7.2 | 0.6% | Jul 22, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bởi Admin 2020 UiP... |
| CVE-2024-38755 | HIGH | 8.8 | 0.7% | Jul 22, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Designinvento Dire... |
| CVE-2024-38708 | HIGH | 8.8 | 0.5% | Jul 22, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dmitry V. (CEO of ... |
| CVE-2024-38701 | HIGH | 8.8 | 0.4% | Jul 22, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects Academy LMS: from n/a t... |
| CVE-2024-38692 | HIGH | 7.2 | 0.7% | Jul 22, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spi... |
| CVE-2024-37942 | HIGH | 7.2 | 0.3% | Jul 22, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Berqier Ltd BerqWP.This issue affects BerqWP: from n/a through 1.7.5... |
| CVE-2024-23321 | HIGH | 8.8 | 0.9% | Jul 22, 2024 | For RocketMQ versions 5.2.0 and below, under certain conditions, there is a risk of exposure of sensitive Information to... |
| CVE-2024-37436 | HIGH | 7.1 | 0.3% | Jul 22, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl... |
| CVE-2024-37391 | HIGH | 7.8 | 0.3% | Jul 22, 2024 | ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{au... |
| CVE-2024-6244 | HIGH | 8.8 | 2.6% | Jul 22, 2024 | The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attack... |
| CVE-2024-5973 | HIGH | 8.8 | 0.5% | Jul 22, 2024 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor ... |
| CVE-2024-6969 | HIGH | 7.5 | 0.4% | Jul 22, 2024 | A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. This i... |
| CVE-2024-6968 | HIGH | 7.5 | 0.4% | Jul 22, 2024 | A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as critical. Thi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now