2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37818 | HIGH | 8.6 | 0.6% | Jun 20, 2024 | Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. ... |
| CVE-2024-37626 | HIGH | 8.8 | 1.8% | Jun 20, 2024 | A command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrar... |
| CVE-2024-37676 | HIGH | 8.4 | 0.2% | Jun 20, 2024 | An issue in htop-dev htop v.2.20 allows a local attacker to cause an out-of-bounds access in the Header_populateFromSett... |
| CVE-2024-6162 | HIGH | 7.5 | 1.7% | Jun 20, 2024 | A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on t... |
| CVE-2024-6189 | HIGH | 8.8 | 1.4% | Jun 20, 2024 | A vulnerability was found in Tenda A301 15.13.08.12. It has been classified as critical. Affected is the function fromSe... |
| CVE-2024-37532 | HIGH | 8.8 | 0.4% | Jun 20, 2024 | IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper... |
| CVE-2024-6185 | HIGH | 8.8 | 9.1% | Jun 20, 2024 | A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC 1.0. Affected by this issue is the fu... |
| CVE-2024-28147 | HIGH | 7.4 | 0.8% | Jun 20, 2024 | An authenticated user can upload arbitrary files in the upload function for collection preview images. An attacker may ... |
| CVE-2024-29012 | HIGH | 7.5 | 0.5% | Jun 20, 2024 | Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause De... |
| CVE-2024-5605 | HIGH | 8.8 | 0.6% | Jun 20, 2024 | The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter wit... |
| CVE-2024-3562 | HIGH | 8.8 | 0.6% | Jun 20, 2024 | The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.... |
| CVE-2024-3561 | HIGH | 8.8 | 0.5% | Jun 20, 2024 | The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versio... |
| CVE-2024-6103 | HIGH | 8.8 | 0.6% | Jun 20, 2024 | Use after free in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap co... |
| CVE-2024-6102 | HIGH | 8.8 | 0.7% | Jun 20, 2024 | Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially ex... |
| CVE-2024-6101 | HIGH | 8.8 | 0.8% | Jun 20, 2024 | Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of ... |
| CVE-2024-6100 | HIGH | 8.8 | 1.1% | Jun 20, 2024 | Type Confusion in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to execute arbitrary code via a ... |
| CVE-2024-36680 | HIGH | 7.5 | 10.1% | Jun 19, 2024 | In the module "Facebook" (pkfacebook) <=1.0.1 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The aj... |
| CVE-2024-36677 | HIGH | 7.5 | 0.4% | Jun 19, 2024 | In the module "Login as customer PRO" (loginascustomerpro) <1.2.7 from Weblir for PrestaShop, a guest can access direct ... |
| CVE-2024-38355 | HIGH | 7.3 | 0.7% | Jun 19, 2024 | Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. A specially crafted Socket.... |
| CVE-2024-36117 | HIGH | 7.5 | 3.1% | Jun 19, 2024 | Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem.... |
| CVE-2024-36115 | HIGH | 7.1 | 0.8% | Jun 19, 2024 | Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem.... |
| CVE-2024-32030 | HIGH | 8.1 | 34.1% | Jun 19, 2024 | Kafka UI is an Open-Source Web UI for Apache Kafka Management. Kafka UI API allows users to connect to different Kafka b... |
| CVE-2024-34444 | HIGH | 8.8 | 0.3% | Jun 19, 2024 | Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a b... |
| CVE-2024-22263 | HIGH | 8.8 | 17.5% | Jun 19, 2024 | Spring Cloud Data Flow is a microservices-based Streaming and Batch data processing in Cloud Foundry and Kubernetes. The... |
| CVE-2024-38616 | HIGH | 8.2 | 0.7% | Jun 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: re-fix fortified-memset warning Th... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now