2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21687 | HIGH | 8.1 | 0.7% | Jul 16, 2024 | This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and ... |
| CVE-2024-21686 | HIGH | 8.7 | 0.9% | Jul 16, 2024 | This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server. This ... |
| CVE-2024-6492 | HIGH | 7.4 | 0.6% | Jul 16, 2024 | Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.... |
| CVE-2024-40516 | HIGH | 8.8 | 0.3% | Jul 16, 2024 | An issue in H3C Technologies Co., Limited H3C Magic RC3000 RC3000V100R009 allows a remote attacker to execute arbitrary ... |
| CVE-2024-33181 | HIGH | 8.8 | 0.6% | Jul 16, 2024 | Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceMac parame... |
| CVE-2024-6089 | HIGH | 7.5 | 2.1% | Jul 16, 2024 | An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent... |
| CVE-2024-40322 | HIGH | 8.8 | 0.4% | Jul 16, 2024 | An issue was discovered in JFinalCMS v.5.0.0. There is a SQL injection vulnerablity via /admin/div_data/data |
| CVE-2024-6655 | HIGH | 7 | 0.5% | Jul 16, 2024 | A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK ap... |
| CVE-2024-32861 | HIGH | 7.8 | 0.1% | Jul 16, 2024 | Under certain circumstances the impacted Software House C•CURE 9000 installer will utilize unnecessarily wide permission... |
| CVE-2024-6435 | HIGH | 8.8 | 0.5% | Jul 16, 2024 | A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privi... |
| CVE-2024-6457 | HIGH | 7.5 | 19.7% | Jul 16, 2024 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection ... |
| CVE-2024-40631 | HIGH | 8.1 | 0.5% | Jul 15, 2024 | Plate media is an open source, rich-text editor for React. Editors that use `MediaEmbedElement` and pass custom `urlPars... |
| CVE-2024-36438 | HIGH | 7.3 | 0.2% | Jul 15, 2024 | eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check... |
| CVE-2024-36434 | HIGH | 7.5 | 0.2% | Jul 15, 2024 | An SMM callout vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmw... |
| CVE-2024-36433 | HIGH | 7.5 | 0.2% | Jul 15, 2024 | An arbitrary memory write vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with... |
| CVE-2024-36432 | HIGH | 7.5 | 0.2% | Jul 15, 2024 | An arbitrary memory write vulnerability was discovered in Supermicro X11DPG-HGX2, X11PDG-QT, X11PDG-OT, and X11PDG-SN mo... |
| CVE-2024-39819 | HIGH | 7.3 | 0.1% | Jul 15, 2024 | Integrity check in the installer for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to co... |
| CVE-2024-27241 | HIGH | 7.5 | 0.4% | Jul 15, 2024 | Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via ... |
| CVE-2024-27240 | HIGH | 7.8 | 0.2% | Jul 15, 2024 | Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a p... |
| CVE-2024-40560 | HIGH | 7.3 | 0.3% | Jul 15, 2024 | Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability. |
| CVE-2024-40554 | HIGH | 7.5 | 0.4% | Jul 15, 2024 | An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information. |
| CVE-2024-6689 | HIGH | 7.8 | 0.2% | Jul 15, 2024 | Local Privilege Escalation in MSI-Installer in baramundi Management Agent v23.1.172.0 on Windows allows a local unprivil... |
| CVE-2024-38494 | HIGH | 8.6 | 0.6% | Jul 15, 2024 | This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected P... |
| CVE-2024-38491 | HIGH | 8.4 | 0.3% | Jul 15, 2024 | The vulnerability allows an unauthenticated attacker to read arbitrary information from the database. |
| CVE-2024-6746 | HIGH | 8.8 | 3.3% | Jul 15, 2024 | A vulnerability classified as problematic was found in NaiboWang EasySpider 0.6.2 on Windows. Affected by this vulnerabi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now