2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37158 | HIGH | 8.1 | 0.4% | Jun 17, 2024 | Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Preliminary checks on actions computed by the cla... |
| CVE-2024-36583 | HIGH | 8.1 | 0.6% | Jun 17, 2024 | A Prototype Pollution issue in byondreal accessor <= 1.0.0 allows an attacker to execute arbitrary code via @byondreal/a... |
| CVE-2024-5650 | HIGH | 8.5 | 0.3% | Jun 17, 2024 | DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an at... |
| CVE-2024-6045 | HIGH | 8.8 | 6.3% | Jun 17, 2024 | Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on ... |
| CVE-2024-6041 | HIGH | 8.8 | 0.5% | Jun 16, 2024 | A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. Affected by this ... |
| CVE-2024-6039 | HIGH | 8.8 | 0.7% | Jun 16, 2024 | A vulnerability, which was classified as critical, was found in Feng Office 3.11.1.2. Affected is an unknown function of... |
| CVE-2024-38467 | HIGH | 7.5 | 0.4% | Jun 16, 2024 | Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API... |
| CVE-2024-38461 | HIGH | 7.5 | 0.4% | Jun 16, 2024 | irodsServerMonPerf in iRODS before 4.3.2 attempts to proceed with use of a path even if it is not a directory. |
| CVE-2024-38459 | HIGH | 7.8 | 0.2% | Jun 16, 2024 | langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an o... |
| CVE-2024-38458 | HIGH | 8.8 | 0.9% | Jun 16, 2024 | Xenforo before 2.2.16 allows code injection. |
| CVE-2024-38457 | HIGH | 8.8 | 7.4% | Jun 16, 2024 | Xenforo before 2.2.16 allows CSRF. |
| CVE-2024-38440 | HIGH | 7.5 | 0.9% | Jun 16, 2024 | Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, beca... |
| CVE-2024-38427 | HIGH | 8.8 | 0.5% | Jun 16, 2024 | In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in Ic... |
| CVE-2024-6008 | HIGH | 8.8 | 0.5% | Jun 15, 2024 | A vulnerability, which was classified as critical, was found in itsourcecode Online Book Store up to 1.0. Affected is an... |
| CVE-2024-27275 | HIGH | 7.8 | 0.2% | Jun 15, 2024 | IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority req... |
| CVE-2024-4551 | HIGH | 8.8 | 0.6% | Jun 15, 2024 | The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusi... |
| CVE-2024-6000 | HIGH | 7.1 | 0.5% | Jun 15, 2024 | The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improp... |
| CVE-2024-3813 | HIGH | 8.8 | 0.7% | Jun 15, 2024 | The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8... |
| CVE-2024-6003 | HIGH | 7.3 | 0.5% | Jun 14, 2024 | A vulnerability was found in Guangdong Baolun Electronics IP Network Broadcasting Service Platform 2.0. It has been clas... |
| CVE-2024-36600 | HIGH | 8.4 | 0.4% | Jun 14, 2024 | Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a craft... |
| CVE-2024-36598 | HIGH | 8.1 | 0.6% | Jun 14, 2024 | An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a cra... |
| CVE-2024-36597 | HIGH | 8.8 | 2.4% | Jun 14, 2024 | Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php. |
| CVE-2024-24320 | HIGH | 8.8 | 4.0% | Jun 14, 2024 | Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sen... |
| CVE-2024-37369 | HIGH | 8.8 | 0.3% | Jun 14, 2024 | A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edi... |
| CVE-2024-37885 | HIGH | 7.8 | 0.3% | Jun 14, 2024 | The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now