2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37882 | HIGH | 8.1 | 0.5% | Jun 14, 2024 | Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshar... |
| CVE-2024-37645 | HIGH | 8.8 | 0.7% | Jun 14, 2024 | TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter... |
| CVE-2024-37643 | HIGH | 8.8 | 0.7% | Jun 14, 2024 | TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter... |
| CVE-2024-37641 | HIGH | 8.8 | 0.6% | Jun 14, 2024 | TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow via the submit-url parameter at /formNewSc... |
| CVE-2024-37644 | HIGH | 8.8 | 0.5% | Jun 14, 2024 | TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, w... |
| CVE-2024-37368 | HIGH | 7.5 | 0.5% | Jun 14, 2024 | A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a u... |
| CVE-2024-37367 | HIGH | 7.5 | 0.5% | Jun 14, 2024 | A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows... |
| CVE-2024-37313 | HIGH | 7.5 | 0.4% | Jun 14, 2024 | Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second fa... |
| CVE-2024-34694 | HIGH | 8.1 | 0.6% | Jun 14, 2024 | LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal ... |
| CVE-2024-33377 | HIGH | 8.1 | 0.4% | Jun 14, 2024 | LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attacker... |
| CVE-2024-37640 | HIGH | 8.8 | 0.6% | Jun 14, 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWiFiEasyG... |
| CVE-2024-37639 | HIGH | 8.8 | 0.6% | Jun 14, 2024 | TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via eport in the function setIpPortFilt... |
| CVE-2024-2024 | HIGH | 8.8 | 3.3% | Jun 14, 2024 | The Folders Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ... |
| CVE-2024-36459 | HIGH | 8.4 | 0.4% | Jun 14, 2024 | A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for ... |
| CVE-2024-5685 | HIGH | 8.1 | 0.4% | Jun 14, 2024 | Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes ... |
| CVE-2024-5995 | HIGH | 8.8 | 0.4% | Jun 14, 2024 | The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the sessi... |
| CVE-2024-31163 | HIGH | 7.2 | 0.6% | Jun 14, 2024 | ASUS Download Master has a buffer overflow vulnerability. An unauthenticated remote attacker with administrative privile... |
| CVE-2024-31162 | HIGH | 7.2 | 0.6% | Jun 14, 2024 | The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote a... |
| CVE-2024-5551 | HIGH | 8.8 | 0.3% | Jun 14, 2024 | The WP STAGING Pro WordPress Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi... |
| CVE-2024-3498 | HIGH | 7.8 | 0.3% | Jun 14, 2024 | Attackers can then execute malicious files by enabling certain services of the printer via the web configuration page an... |
| CVE-2024-3497 | HIGH | 8.8 | 0.7% | Jun 14, 2024 | Path traversal vulnerability in the web server of the Toshiba printer enables attacker to overwrite orginal files or add... |
| CVE-2024-3496 | HIGH | 8.8 | 0.7% | Jun 14, 2024 | Attackers can bypass the web login authentication process to gain access to the printer's system information and upload ... |
| CVE-2024-1094 | HIGH | 7.3 | 0.5% | Jun 14, 2024 | The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress... |
| CVE-2024-31161 | HIGH | 7.2 | 0.5% | Jun 14, 2024 | The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrati... |
| CVE-2024-27178 | HIGH | 7.2 | 1.5% | Jun 14, 2024 | An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying file name var... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now