2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33529 | HIGH | 7.2 | 0.9% | May 21, 2024 | ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrativ... |
| CVE-2024-33526 | HIGH | 7.1 | 0.5% | May 21, 2024 | A Stored Cross-site Scripting (XSS) vulnerability in the "Import of user role and title of user role" feature in ILIAS 7... |
| CVE-2024-35386 | HIGH | 7.5 | 0.6% | May 21, 2024 | An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_do_gc function in the m... |
| CVE-2024-4420 | HIGH | 7.5 | 0.2% | May 21, 2024 | There exists a Denial of service vulnerability in Tink-cc in versions prior to 2.1.3. * An adversary can crash binari... |
| CVE-2024-4988 | HIGH | 7.5 | 0.4% | May 21, 2024 | The mobile application (com.transsion.videocallenhancer) interface has improper permission control, which can lead to th... |
| CVE-2024-4435 | HIGH | 7.5 | 0.5% | May 21, 2024 | When storing unbounded types in a BTreeMap, a node is represented as a linked list of "memory chunks". It was discovered... |
| CVE-2024-4566 | HIGH | 7.1 | 0.4% | May 21, 2024 | The ShopLentor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2024-4290 | HIGH | 7.1 | 0.4% | May 21, 2024 | The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could all... |
| CVE-2024-5145 | HIGH | 8.8 | 0.7% | May 20, 2024 | A vulnerability was found in SourceCodester Vehicle Management System up to 1.0 and classified as critical. This issue a... |
| CVE-2024-34710 | HIGH | 7.1 | 0.4% | May 20, 2024 | Wiki.js is al wiki app built on Node.js. Client side template injection was discovered, that could allow an attacker to ... |
| CVE-2024-35579 | HIGH | 7.7 | 0.4% | May 20, 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv. |
| CVE-2024-35578 | HIGH | 8 | 0.4% | May 20, 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv. |
| CVE-2024-34949 | HIGH | 8.2 | 0.4% | May 20, 2024 | SQL injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function Orde... |
| CVE-2024-34193 | HIGH | 7.5 | 0.6% | May 20, 2024 | smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vu... |
| CVE-2024-31714 | HIGH | 7.5 | 0.4% | May 20, 2024 | Buffer Overflow vulnerability in Waxlab wax v.0.9-3 and before allows an attacker to cause a denial of service via the L... |
| CVE-2024-29651 | HIGH | 8.1 | 0.8% | May 20, 2024 | A Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to ex... |
| CVE-2024-24293 | HIGH | 8.8 | 0.7% | May 20, 2024 | A Prototype Pollution issue in MiguelCastillo @bit/loader v.10.0.3 allows an attacker to execute arbitrary code via the ... |
| CVE-2024-34948 | HIGH | 7.5 | 0.4% | May 20, 2024 | An issue in Quanxun Huiju Network Technology(Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 allows attackers to ... |
| CVE-2024-0401 | HIGH | 7.2 | 0.7% | May 20, 2024 | ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and r... |
| CVE-2024-4151 | HIGH | 8.1 | 0.4% | May 20, 2024 | An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users can view and update any p... |
| CVE-2024-3482 | HIGH | 8.7 | 0.4% | May 20, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager a... |
| CVE-2024-34953 | HIGH | 7.5 | 0.6% | May 20, 2024 | An issue in taurusxin ncmdump v1.3.2 allows attackers to cause a Denial of Service (DoS) via memory exhaustion by supply... |
| CVE-2024-2835 | HIGH | 8.7 | 0.4% | May 20, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager a... |
| CVE-2024-4287 | HIGH | 7.2 | 0.6% | May 20, 2024 | In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. ... |
| CVE-2024-27312 | HIGH | 8.1 | 0.9% | May 20, 2024 | Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged use... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now