2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42020 | MEDIUM | 5.4 | 0.4% | Sep 7, 2024 | A Cross-site-scripting (XSS) vulnerability exists in the Reporter Widgets that allows HTML injection. |
| CVE-2024-42019 | HIGH | 8 | 0.5% | Sep 7, 2024 | A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This atta... |
| CVE-2024-40718 | HIGH | 8.8 | 0.5% | Sep 7, 2024 | A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through e... |
| CVE-2024-40714 | HIGH | 8.3 | 0.3% | Sep 7, 2024 | An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to... |
| CVE-2024-40713 | HIGH | 7.8 | 0.3% | Sep 7, 2024 | A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alte... |
| CVE-2024-40712 | HIGH | 7.8 | 0.3% | Sep 7, 2024 | A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perfor... |
| CVE-2024-40711 | CRITICAL | 9.8 | 88.2% | Sep 7, 2024 | A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec... |
| CVE-2024-40710 | HIGH | 8.8 | 1.1% | Sep 7, 2024 | A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service ... |
| CVE-2024-40709 | HIGH | 7.8 | 0.2% | Sep 7, 2024 | A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to ... |
| CVE-2024-39718 | HIGH | 8.1 | 0.8% | Sep 7, 2024 | An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with... |
| CVE-2024-39715 | HIGH | 8.5 | 0.9% | Sep 7, 2024 | A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitra... |
| CVE-2024-39714 | CRITICAL | 9.9 | 1.2% | Sep 7, 2024 | A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to re... |
| CVE-2024-38651 | HIGH | 8.5 | 0.9% | Sep 7, 2024 | A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to... |
| CVE-2024-38650 | CRITICAL | 9.9 | 0.9% | Sep 7, 2024 | An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on... |
| CVE-2024-8558 | MEDIUM | 4.3 | 0.6% | Sep 7, 2024 | A vulnerability classified as problematic was found in SourceCodester Food Ordering Management System 1.0. This vulnerab... |
| CVE-2024-36138 | HIGH | 8.1 | 1.1% | Sep 7, 2024 | Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions ... |
| CVE-2024-36137 | LOW | 3.3 | 0.4% | Sep 7, 2024 | A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs... |
| CVE-2024-8557 | HIGH | 7.5 | 0.5% | Sep 7, 2024 | A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System 1.0. This affect... |
| CVE-2024-8555 | MEDIUM | 6.1 | 0.6% | Sep 7, 2024 | A vulnerability was found in SourceCodester Clinics Patient Management System 2.0. It has been classified as problematic... |
| CVE-2024-40681 | HIGH | 8.8 | 0.5% | Sep 7, 2024 | IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically define... |
| CVE-2024-8554 | MEDIUM | 5.4 | 0.5% | Sep 7, 2024 | A vulnerability was found in SourceCodester Clinics Patient Management System 2.0 and classified as problematic. This is... |
| CVE-2024-40680 | MEDIUM | 5.5 | 0.2% | Sep 7, 2024 | IBM MQ 9.3 CD and 9.4 LTS/CD could allow a local user to cause a denial of service due to improper memory allocation cau... |
| CVE-2024-37068 | HIGH | 7.5 | 0.2% | Sep 7, 2024 | IBM Maximo Application Suite - Manage Component 8.10, 8.11, and 9.0 uses weaker than expected cryptographic algorithms t... |
| CVE-2024-7620 | MEDIUM | 6.6 | 0.7% | Sep 7, 2024 | The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid... |
| CVE-2024-7112 | MEDIUM | 6.5 | 0.5% | Sep 7, 2024 | The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘s... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now