2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3555 | HIGH | 7.2 | 0.3% | Jun 4, 2024 | The Social Link Pages: link-in-bio landing pages for your social media profiles plugin for WordPress is vulnerable to un... |
| CVE-2024-2019 | HIGH | 7.5 | 0.4% | Jun 4, 2024 | The WP-DB-Table-Editor plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss... |
| CVE-2024-4870 | HIGH | 7.2 | 0.5% | Jun 4, 2024 | The Frontend Registration – Contact Form 7 plugin for WordPress is vulnerable to privilege escalation in versions up to,... |
| CVE-2024-4540 | HIGH | 7.5 | 0.6% | Jun 3, 2024 | A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to ... |
| CVE-2024-32983 | HIGH | 7.5 | 0.4% | Jun 3, 2024 | Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSO... |
| CVE-2024-36128 | HIGH | 7.5 | 0.6% | Jun 3, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.2, providing a non-numer... |
| CVE-2024-36127 | HIGH | 7.5 | 0.4% | Jun 3, 2024 | apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in l... |
| CVE-2024-36728 | HIGH | 8.1 | 5.2% | Jun 3, 2024 | TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows... |
| CVE-2024-36569 | HIGH | 8.1 | 0.6% | Jun 3, 2024 | Sourcecodester Gas Agency Management System v1.0 is vulnerable to arbitrary code execution via editClientImage.php. |
| CVE-2024-35631 | HIGH | 7.1 | 0.3% | Jun 3, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foliovision... |
| CVE-2024-35630 | HIGH | 7.6 | 0.4% | Jun 3, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LJ Apps WP TripAdv... |
| CVE-2024-23670 | HIGH | 8.8 | 0.4% | Jun 3, 2024 | An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,... |
| CVE-2024-23668 | HIGH | 8.8 | 0.7% | Jun 3, 2024 | An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,... |
| CVE-2024-23667 | HIGH | 8.8 | 0.4% | Jun 3, 2024 | An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,... |
| CVE-2024-23665 | HIGH | 8.8 | 0.5% | Jun 3, 2024 | Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, ... |
| CVE-2024-23363 | HIGH | 7.5 | 0.3% | Jun 3, 2024 | Transient DOS while processing an improperly formatted Fine Time Measurement (FTM) management frame. |
| CVE-2024-23360 | HIGH | 7.8 | 0.1% | Jun 3, 2024 | Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers. |
| CVE-2024-36963 | HIGH | 7.8 | 0.2% | Jun 3, 2024 | In the Linux kernel, the following vulnerability has been resolved: tracefs: Reset permissions on remount if permission... |
| CVE-2024-36960 | HIGH | 7.1 | 0.3% | Jun 3, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix invalid reads in fence signaled eve... |
| CVE-2024-20066 | HIGH | 7.5 | 0.7% | Jun 3, 2024 | In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote denial of ... |
| CVE-2024-5588 | HIGH | 8.8 | 0.6% | Jun 2, 2024 | A vulnerability was found in itsourcecode Learning Management System 1.0. It has been declared as critical. Affected by ... |
| CVE-2024-36391 | HIGH | 7.4 | 0.4% | Jun 2, 2024 | MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic |
| CVE-2024-36390 | HIGH | 7.5 | 0.4% | Jun 2, 2024 | MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service |
| CVE-2024-2178 | HIGH | 7.5 | 0.6% | Jun 2, 2024 | A path traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'copy_to_custom_personas' en... |
| CVE-2024-4148 | HIGH | 7.5 | 0.6% | Jun 1, 2024 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary application, version 1.2.10.... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now