2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6637 | HIGH | 7.3 | 0.4% | Jul 20, 2024 | The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all version... |
| CVE-2024-6635 | HIGH | 7.3 | 0.4% | Jul 20, 2024 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ... |
| CVE-2024-38696 | HIGH | 7.1 | 0.3% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho CRM Zo... |
| CVE-2024-38694 | HIGH | 7.1 | 0.3% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Moloni allo... |
| CVE-2024-38683 | HIGH | 7.1 | 0.4% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in iThemelandC... |
| CVE-2024-38680 | HIGH | 7.1 | 0.3% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Appmaker Ap... |
| CVE-2024-38673 | HIGH | 7.1 | 0.3% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Obtain Info... |
| CVE-2024-38672 | HIGH | 7.1 | 0.4% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in namithjawah... |
| CVE-2024-38669 | HIGH | 7.1 | 0.4% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in a3rev Softw... |
| CVE-2024-37961 | HIGH | 7.1 | 0.3% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in codoc.Jp al... |
| CVE-2024-6281 | HIGH | 7.3 | 0.3% | Jul 20, 2024 | A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `... |
| CVE-2024-40348 | HIGH | 8.2 | 8.3% | Jul 20, 2024 | An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory... |
| CVE-2024-41122 | HIGH | 8.8 | 0.6% | Jul 19, 2024 | Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can t... |
| CVE-2024-41121 | HIGH | 8.8 | 0.7% | Jul 19, 2024 | Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can t... |
| CVE-2024-39906 | HIGH | 8.3 | 1.0% | Jul 19, 2024 | A command injection vulnerability was found in the IndieAuth functionality of the Ruby on Rails based Haven blog web app... |
| CVE-2024-40400 | HIGH | 8.8 | 0.8% | Jul 19, 2024 | An arbitrary file upload vulnerability in the image upload function of Automad v2.0.0 allows attackers to execute arbitr... |
| CVE-2024-41600 | HIGH | 7.5 | 0.4% | Jul 19, 2024 | Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive... |
| CVE-2024-41602 | HIGH | 8.8 | 0.2% | Jul 19, 2024 | Cross Site Request Forgery vulnerability in Spina CMS v.2.18.0 and before allows a remote attacker to escalate privilege... |
| CVE-2024-41601 | HIGH | 7.5 | 0.5% | Jul 19, 2024 | Insecure Permissions vulnerability in lin-CMS v.0.2.0 and before allows a remote attacker to obtain sensitive informatio... |
| CVE-2024-41492 | HIGH | 7.5 | 0.6% | Jul 19, 2024 | A stack overflow in Tenda AX1806 v1.0.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. |
| CVE-2024-41281 | HIGH | 8.8 | 0.3% | Jul 19, 2024 | Linksys WRT54G v4.21.5 has a stack overflow vulnerability in get_merge_mac function. |
| CVE-2024-39963 | HIGH | 8 | 1.5% | Jul 19, 2024 | AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01... |
| CVE-2024-27489 | HIGH | 7.5 | 0.4% | Jul 19, 2024 | An issue in the DelFile() function of WMCMS v4.4 allows attackers to delete arbitrary files via a crafted POST request. |
| CVE-2024-37066 | HIGH | 8.8 | 1.8% | Jul 19, 2024 | A command injection vulnerability exists in Wyze V4 Pro firmware versions before 4.50.4.9222, which allows attackers to ... |
| CVE-2024-41107 | HIGH | 8.1 | 17.8% | Jul 19, 2024 | The CloudStack SAML authentication (disabled by default) does not enforce signature check. In CloudStack environments wh... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now