2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22385 | MEDIUM | 4.4 | 0.1% | Jun 25, 2024 | Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read an... |
| CVE-2024-22168 | MEDIUM | 5.9 | 0.3% | Jun 24, 2024 | A Cross-Site Scripting (XSS) vulnerability on the My Cloud, My Cloud Home, SanDisk ibi, and WD Cloud web apps was found ... |
| CVE-2024-38903 | MEDIUM | 4.1 | 0.4% | Jun 24, 2024 | H3C Magic R230 V100R002's udpserver opens port 9034, allowing attackers to execute arbitrary commands. |
| CVE-2024-38897 | MEDIUM | 5.3 | 0.4% | Jun 24, 2024 | WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information. |
| CVE-2024-38896 | MEDIUM | 5.3 | 1.2% | Jun 24, 2024 | WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi. |
| CVE-2024-38895 | MEDIUM | 5.3 | 0.4% | Jun 24, 2024 | WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information. |
| CVE-2024-38894 | MEDIUM | 5.3 | 1.2% | Jun 24, 2024 | WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi. |
| CVE-2024-38892 | MEDIUM | 6.5 | 0.4% | Jun 24, 2024 | An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh compon... |
| CVE-2024-37681 | MEDIUM | 6.5 | 0.5% | Jun 24, 2024 | An issue the background management system of Shanxi Internet Chuangxiang Technology Co., Ltd v1.0.1 allows a remote atta... |
| CVE-2024-37678 | MEDIUM | 5.3 | 0.3% | Jun 24, 2024 | Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows... |
| CVE-2024-34312 | MEDIUM | 6.1 | 0.8% | Jun 24, 2024 | Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via... |
| CVE-2024-37732 | MEDIUM | 6.1 | 16.0% | Jun 24, 2024 | Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a craft... |
| CVE-2024-37680 | MEDIUM | 6.1 | 0.4% | Jun 24, 2024 | Hangzhou Meisoft Information Technology Co., Ltd. FineSoft <=8.0 is affected by Cross Site Scripting (XSS) which allows ... |
| CVE-2024-37679 | MEDIUM | 6.1 | 0.4% | Jun 24, 2024 | Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows... |
| CVE-2024-6104 | MEDIUM | 5.5 | 0.4% | Jun 24, 2024 | go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryable... |
| CVE-2024-38369 | MEDIUM | 4.3 | 0.3% | Jun 24, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The content of ... |
| CVE-2024-33881 | MEDIUM | 5.3 | 0.5% | Jun 24, 2024 | An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileD... |
| CVE-2024-33880 | MEDIUM | 5.3 | 0.3% | Jun 24, 2024 | An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathname... |
| CVE-2024-6285 | MEDIUM | 6.7 | 0.2% | Jun 24, 2024 | Integer Underflow (Wrap or Wraparound) vulnerability in Renesas arm-trusted-firmware. An integer underflow in image rang... |
| CVE-2024-39292 | MEDIUM | 5.5 | 0.2% | Jun 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: um: Add winch to winch_handlers before registering ... |
| CVE-2024-38663 | MEDIUM | 5.5 | 0.2% | Jun 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix list corruption from resetting io s... |
| CVE-2024-37825 | MEDIUM | 5.4 | 0.4% | Jun 24, 2024 | An issue in EnvisionWare Computer Access & Reservation Control SelfCheck v1.0 (fixed in OneStop 3.2.0.27184 Hotfix May 2... |
| CVE-2024-37026 | MEDIUM | 5.5 | 0.2% | Jun 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Only use reserved BCS instances for usm mig... |
| CVE-2024-37021 | MEDIUM | 5.5 | 0.2% | Jun 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: fpga: manager: add owner module and take its refcou... |
| CVE-2024-36479 | MEDIUM | 5.5 | 0.2% | Jun 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: fpga: bridge: add owner module and take its refcoun... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now