2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6407 | HIGH | 7.5 | 0.4% | Jul 11, 2024 | CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted m... |
| CVE-2024-5681 | HIGH | 7.8 | 0.2% | Jul 11, 2024 | CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, a... |
| CVE-2024-5679 | HIGH | 7.1 | 0.1% | Jul 11, 2024 | CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a... |
| CVE-2024-2602 | HIGH | 7.8 | 0.3% | Jul 11, 2024 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could r... |
| CVE-2024-6666 | HIGH | 8.8 | 0.5% | Jul 11, 2024 | The WP ERP plugin for WordPress is vulnerable to SQL Injection via the ‘vendor_id’ and 'status' parameter in all version... |
| CVE-2024-1845 | HIGH | 8.8 | 0.3% | Jul 11, 2024 | The VikRentCar Car Rental Management System WordPress plugin before 1.3.2 does not have CSRF checks in some places, whic... |
| CVE-2024-22280 | HIGH | 8.1 | 0.5% | Jul 11, 2024 | VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authent... |
| CVE-2024-6676 | HIGH | 8.8 | 0.4% | Jul 11, 2024 | A vulnerability has been found in witmy my-springsecurity-plus up to 2024-07-03 and classified as critical. Affected by ... |
| CVE-2024-6447 | HIGH | 7.2 | 0.5% | Jul 11, 2024 | The FULL – Cliente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the license plan parameter in a... |
| CVE-2024-6652 | HIGH | 8.8 | 0.6% | Jul 10, 2024 | A vulnerability was found in itsourcecode Gym Management System 1.0. It has been classified as critical. This affects an... |
| CVE-2024-39565 | HIGH | 8.8 | 0.5% | Jul 10, 2024 | An Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in J-Web shipped with Juni... |
| CVE-2024-39562 | HIGH | 8.7 | 0.4% | Jul 10, 2024 | A Missing Release of Resource after Effective Lifetime vulnerability the xinetd process, responsible for spawning SSH da... |
| CVE-2024-39560 | HIGH | 7.1 | 0.2% | Jul 10, 2024 | An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Ju... |
| CVE-2024-39559 | HIGH | 8.2 | 0.4% | Jul 10, 2024 | An Improper Check for Unusual or Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS ... |
| CVE-2024-39558 | HIGH | 7.1 | 0.3% | Jul 10, 2024 | An Unchecked Return Value vulnerability in the Routing Protocol Daemon (rpd) on Juniper Networks Junos OS and Juniper Ne... |
| CVE-2024-39557 | HIGH | 7.1 | 0.2% | Jul 10, 2024 | An Uncontrolled Resource Consumption vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Network... |
| CVE-2024-39556 | HIGH | 7 | 0.1% | Jul 10, 2024 | A Stack-Based Buffer Overflow vulnerability in Juniper Networks Junos OS and Juniper Networks Junos OS Evolved may allow... |
| CVE-2024-39555 | HIGH | 8.7 | 0.5% | Jul 10, 2024 | An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Ju... |
| CVE-2024-39554 | HIGH | 8.2 | 0.4% | Jul 10, 2024 | A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability the Routin... |
| CVE-2024-39518 | HIGH | 8.7 | 0.4% | Jul 10, 2024 | A Heap-based Buffer Overflow vulnerability in the telemetry sensor process (sensord) of Juniper Networks Junos OS on MX2... |
| CVE-2024-39517 | HIGH | 7.1 | 0.2% | Jul 10, 2024 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) on ... |
| CVE-2024-39514 | HIGH | 7.1 | 0.2% | Jul 10, 2024 | An Improper Check or Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Ne... |
| CVE-2024-39512 | HIGH | 7 | 0.2% | Jul 10, 2024 | An Improper Physical Access Control vulnerability in the console port control of Juniper Networks Junos OS Evolved allow... |
| CVE-2024-6286 | HIGH | 7.8 | 0.4% | Jul 10, 2024 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows |
| CVE-2024-6236 | HIGH | 7.5 | 0.7% | Jul 10, 2024 | Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now