2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42915 | HIGH | 8 | 0.4% | Aug 23, 2024 | A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token... |
| CVE-2024-42766 | MEDIUM | 5.4 | 0.3% | Aug 23, 2024 | Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php. |
| CVE-2024-42765 | CRITICAL | 9.8 | 0.7% | Aug 23, 2024 | A SQL injection vulnerability in "/login.php" of the Kashipara Bus Ticket Reservation System v1.0 allows remote attacker... |
| CVE-2024-42764 | CRITICAL | 9.4 | 0.3% | Aug 23, 2024 | Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php. |
| CVE-2024-42040 | HIGH | 8.1 | 0.6% | Aug 23, 2024 | Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today o... |
| CVE-2024-41150 | MEDIUM | 6.1 | 1.2% | Aug 23, 2024 | An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDe... |
| CVE-2024-38869 | MEDIUM | 5.4 | 1.0% | Aug 23, 2024 | Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configu... |
| CVE-2024-37311 | HIGH | 8.2 | 0.2% | Aug 23, 2024 | Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, ... |
| CVE-2024-5586 | HIGH | 8.8 | 5.2% | Aug 23, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet loc... |
| CVE-2024-5556 | HIGH | 8.8 | 4.5% | Aug 23, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports modu... |
| CVE-2024-5490 | HIGH | 8.8 | 4.0% | Aug 23, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate re... |
| CVE-2024-5467 | HIGH | 8.8 | 4.5% | Aug 23, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lock... |
| CVE-2024-5466 | HIGH | 8.8 | 6.9% | Aug 23, 2024 | Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the aut... |
| CVE-2024-36517 | HIGH | 8.8 | 5.3% | Aug 23, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts modul... |
| CVE-2024-36516 | HIGH | 8.8 | 4.4% | Aug 23, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. N... |
| CVE-2024-36515 | HIGH | 8.8 | 4.5% | Aug 23, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. N... |
| CVE-2024-36514 | HIGH | 8.8 | 4.0% | Aug 23, 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary... |
| CVE-2024-43883 | HIGH | 7 | 0.2% | Aug 23, 2024 | In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new re... |
| CVE-2024-7986 | HIGH | 7.5 | 0.6% | Aug 23, 2024 | A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensiti... |
| CVE-2024-5502 | MEDIUM | 5.4 | 0.3% | Aug 23, 2024 | The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Imag... |
| CVE-2024-38807 | MEDIUM | 6.3 | 0.1% | Aug 23, 2024 | Applications that use spring-boot-loader or spring-boot-loader-classic and contain custom code that performs signature v... |
| CVE-2024-43105 | MEDIUM | 4.3 | 0.4% | Aug 23, 2024 | Mattermost Plugin Channel Export versions <=1.0.0 fail to restrict concurrent runs of the /export command which allows a... |
| CVE-2024-40766 | CRITICAL | 9.8 | 15.7% | Aug 23, 2024 | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially lea... |
| CVE-2024-6715 | MEDIUM | 6.1 | 0.3% | Aug 23, 2024 | The Ditty WordPress plugin before 3.1.46 re-introduced a previously fixed security issue (https://wpscan.com/vulnerabil... |
| CVE-2024-3282 | MEDIUM | 4.8 | 0.3% | Aug 23, 2024 | The WP Table Builder WordPress plugin through 1.5.0 does not sanitise and escape some of its Table data, which could al... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now