2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5911 | MEDIUM | 4.9 | 0.6% | Jul 10, 2024 | An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write admin... |
| CVE-2024-5492 | MEDIUM | 6.1 | 0.6% | Jul 10, 2024 | Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScale... |
| CVE-2024-37147 | MEDIUM | 4.3 | 0.7% | Jul 10, 2024 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track... |
| CVE-2024-27095 | MEDIUM | 4.8 | 0.3% | Jul 10, 2024 | Decidim is a participatory democracy framework. The admin panel is subject to potential XSS attach in case the attacker ... |
| CVE-2024-27090 | MEDIUM | 5.3 | 0.5% | Jul 10, 2024 | Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City go... |
| CVE-2024-6647 | MEDIUM | 5.1 | 0.5% | Jul 10, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Croogo up to 4.0.7. This affect... |
| CVE-2024-6646 | MEDIUM | 6.9 | 46.0% | Jul 10, 2024 | A vulnerability was found in Netgear WN604 up to 20240710. It has been rated as problematic. Affected by this issue is s... |
| CVE-2024-37504 | MEDIUM | 5.3 | 0.4% | Jul 10, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FileBird Document Library.This is... |
| CVE-2024-37498 | MEDIUM | 5.3 | 0.4% | Jul 10, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pauple Table & Contact Form 7 Database – Tab... |
| CVE-2024-37270 | MEDIUM | 5.3 | 0.4% | Jul 10, 2024 | Insertion of Sensitive Information into Log File vulnerability in TrustedLogin TrustedLogin Vendor.This issue affects Tr... |
| CVE-2024-37205 | MEDIUM | 5.3 | 0.4% | Jul 10, 2024 | Insertion of Sensitive Information into Log File vulnerability in SERVIT Software Solutions.This issue affects affiliate... |
| CVE-2024-6645 | MEDIUM | 6.3 | 0.5% | Jul 10, 2024 | A vulnerability was found in WuKongOpenSource Wukong_nocode up to 20230807. It has been declared as critical. Affected b... |
| CVE-2024-6644 | MEDIUM | 6.3 | 0.5% | Jul 10, 2024 | A vulnerability was found in zmops ArgusDBM up to 0.1.0. It has been classified as critical. Affected is the function ge... |
| CVE-2024-5178 | MEDIUM | 6.9 | 33.6% | Jul 10, 2024 | ServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Ut... |
| CVE-2024-40417 | MEDIUM | 6.5 | 0.4% | Jul 10, 2024 | A vulnerability was found in Tenda AX1806 1.0.0.1. Affected by this issue is the function formSetRebootTimer of the file... |
| CVE-2024-40412 | MEDIUM | 6.8 | 0.3% | Jul 10, 2024 | Tenda AX12 v1.0 v22.03.01.46 contains a stack overflow in the deviceList parameter of the sub_42E410 function. |
| CVE-2024-20456 | MEDIUM | 6.7 | 0.2% | Jul 10, 2024 | A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high priv... |
| CVE-2024-40336 | MEDIUM | 6.1 | 0.4% | Jul 10, 2024 | idccms v1.35 is vulnerable to Cross Site Scripting (XSS) within the 'Image Advertising Management.' |
| CVE-2024-40328 | MEDIUM | 6.3 | 0.2% | Jul 10, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/memberOnline_deal.ph... |
| CVE-2024-6556 | MEDIUM | 5.3 | 0.4% | Jul 10, 2024 | The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to Full Path Disclo... |
| CVE-2024-5664 | MEDIUM | 5.4 | 0.3% | Jul 10, 2024 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2024-39493 | MEDIUM | 5.5 | 0.2% | Jul 10, 2024 | In the Linux kernel, the following vulnerability has been resolved: crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak U... |
| CVE-2024-39491 | MEDIUM | 5.5 | 0.2% | Jul 10, 2024 | In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l56: Fix lifetime of cs_dsp instance... |
| CVE-2024-39490 | MEDIUM | 6.2 | 0.2% | Jul 10, 2024 | In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix missing sk_buff release in seg6_input... |
| CVE-2024-39489 | MEDIUM | 5.5 | 0.2% | Jul 10, 2024 | In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix memleak in seg6_hmac_init_algo seg6_... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now