2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39937 | HIGH | 7.5 | 0.9% | Jul 4, 2024 | supOS 5.0 allows api/image/download?fileName=../ directory traversal for reading files. |
| CVE-2024-39935 | HIGH | 8.8 | 0.9% | Jul 4, 2024 | jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated u... |
| CVE-2024-39934 | HIGH | 7.8 | 0.2% | Jul 4, 2024 | Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup ... |
| CVE-2024-39933 | HIGH | 7.7 | 0.7% | Jul 4, 2024 | Gogs through 0.13.0 allows argument injection during the tagging of a new release. |
| CVE-2024-6506 | HIGH | 8.2 | 0.5% | Jul 4, 2024 | Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This ... |
| CVE-2024-6507 | HIGH | 8.1 | 1.1% | Jul 4, 2024 | Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API |
| CVE-2024-5943 | HIGH | 8.8 | 0.3% | Jul 4, 2024 | The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2024-6319 | HIGH | 8.8 | 0.9% | Jul 4, 2024 | The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u... |
| CVE-2024-6318 | HIGH | 8.8 | 0.9% | Jul 4, 2024 | The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u... |
| CVE-2024-3904 | HIGH | 8.8 | 0.2% | Jul 4, 2024 | Incorrect Default Permissions vulnerability in Smart Device Communication Gateway preinstalled on MELIPC Series MI5122-V... |
| CVE-2024-1182 | HIGH | 7 | 0.3% | Jul 4, 2024 | Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi E... |
| CVE-2024-2385 | HIGH | 8.8 | 0.9% | Jul 4, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i... |
| CVE-2024-38345 | HIGH | 8.1 | 0.3% | Jul 4, 2024 | A cross-site request forgery vulnerability exists in Sola Testimonials versions prior to 3.0.0. If this vulnerability is... |
| CVE-2024-6284 | HIGH | 7.3 | 0.3% | Jul 3, 2024 | In https://github.com/google/nftables IP addresses were encoded in the wrong byte order, resulting in an nftables conf... |
| CVE-2024-34750 | HIGH | 7.5 | 4.6% | Jul 3, 2024 | Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When proc... |
| CVE-2024-33871 | HIGH | 8.8 | 1.4% | Jul 3, 2024 | An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution v... |
| CVE-2024-29511 | HIGH | 7.5 | 1.1% | Jul 3, 2024 | Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrar... |
| CVE-2024-35227 | HIGH | 7.5 | 0.6% | Jul 3, 2024 | Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 o... |
| CVE-2024-29509 | HIGH | 8.8 | 1.4% | Jul 3, 2024 | Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the ... |
| CVE-2024-29506 | HIGH | 8.8 | 0.9% | Jul 3, 2024 | Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF ... |
| CVE-2024-6471 | HIGH | 8.8 | 0.6% | Jul 3, 2024 | A vulnerability classified as critical has been found in SourceCodester Online Tours & Travels Management 1.0. This affe... |
| CVE-2024-5672 | HIGH | 7.2 | 1.2% | Jul 3, 2024 | A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization ... |
| CVE-2024-6427 | HIGH | 7.5 | 0.6% | Jul 3, 2024 | Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can u... |
| CVE-2024-6426 | HIGH | 7.1 | 0.3% | Jul 3, 2024 | Information exposure vulnerability in MESbook 20221021.03 version, the exploitation of which could allow a local attacke... |
| CVE-2024-6469 | HIGH | 8.8 | 0.7% | Jul 3, 2024 | A vulnerability was found in playSMS 1.4.3. It has been declared as problematic. Affected by this vulnerability is an un... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now