2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6310 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | The Advanced AJAX Page Loader plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload ... |
| CVE-2024-6309 | HIGH | 8.8 | 0.4% | Jul 9, 2024 | The Attachment File Icons (AF Icons) plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File ... |
| CVE-2024-6180 | HIGH | 7.2 | 0.5% | Jul 9, 2024 | The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2024-6161 | HIGH | 8.8 | 0.8% | Jul 9, 2024 | The Default Thumbnail Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2024-6123 | HIGH | 7.2 | 1.0% | Jul 9, 2024 | The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ic... |
| CVE-2024-28750 | HIGH | 7.2 | 0.8% | Jul 9, 2024 | A remote attacker with high privileges may use a deleting file function to inject OS commands. |
| CVE-2024-28749 | HIGH | 7.2 | 0.8% | Jul 9, 2024 | A remote attacker with high privileges may use a writing file function to inject OS commands. |
| CVE-2024-28748 | HIGH | 7.2 | 0.8% | Jul 9, 2024 | A remote attacker with high privileges may use a reading file function to inject OS commands. |
| CVE-2024-22062 | HIGH | 8.8 | 0.2% | Jul 9, 2024 | There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permis... |
| CVE-2024-5441 | HIGH | 8.8 | 1.1% | Jul 9, 2024 | The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2024-6166 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based ... |
| CVE-2024-39598 | HIGH | 7.7 | 0.3% | Jul 9, 2024 | SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal... |
| CVE-2024-39597 | HIGH | 7.2 | 0.3% | Jul 9, 2024 | In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B si... |
| CVE-2024-5974 | HIGH | 7.2 | 0.9% | Jul 9, 2024 | A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management ... |
| CVE-2024-4944 | HIGH | 7.8 | 0.3% | Jul 9, 2024 | A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user t... |
| CVE-2024-5793 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter i... |
| CVE-2024-5549 | HIGH | 8.1 | 0.3% | Jul 9, 2024 | A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs,... |
| CVE-2024-5971 | HIGH | 7.5 | 2.9% | Jul 8, 2024 | A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers... |
| CVE-2024-6227 | HIGH | 7.5 | 0.6% | Jul 8, 2024 | A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tr... |
| CVE-2024-6409 | HIGH | 7 | 27.9% | Jul 8, 2024 | A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacke... |
| CVE-2024-39701 | HIGH | 7.7 | 0.4% | Jul 8, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly... |
| CVE-2024-39202 | HIGH | 8.8 | 1.4% | Jul 8, 2024 | D-Link DIR-823X firmware - 240126 was discovered to contain a remote command execution (RCE) vulnerability via the dhcpd... |
| CVE-2024-31504 | HIGH | 7.5 | 0.6% | Jul 8, 2024 | Buffer Overflow vulnerability in SILA Embedded Solutions GmbH freemodbus v.2018-09-12 allows a remtoe attacker to cause ... |
| CVE-2024-23562 | HIGH | 7.5 | 0.5% | Jul 8, 2024 | A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthen... |
| CVE-2024-21778 | HIGH | 7.2 | 0.9% | Jul 8, 2024 | A heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realte... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now