2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39398 | HIGH | 7.4 | 0.8% | Aug 14, 2024 | Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Restriction of Ex... |
| CVE-2024-39397 | CRITICAL | 9 | 1.1% | Aug 14, 2024 | Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Unrestricted Upload of Fil... |
| CVE-2024-6532 | MEDIUM | 6.4 | 0.3% | Aug 14, 2024 | The Sheet to Table Live Sync for Google Sheet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2024-38483 | MEDIUM | 6.7 | 0.2% | Aug 14, 2024 | Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged at... |
| CVE-2024-4389 | HIGH | 8.8 | 1.0% | Aug 14, 2024 | The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing f... |
| CVE-2024-41864 | HIGH | 7.8 | 0.3% | Aug 14, 2024 | Substance3D - Designer versions 13.1.2 and earlier are affected by an out-of-bounds write vulnerability that could resul... |
| CVE-2024-41863 | MEDIUM | 5.5 | 0.2% | Aug 14, 2024 | Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to di... |
| CVE-2024-41862 | MEDIUM | 5.5 | 0.2% | Aug 14, 2024 | Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to di... |
| CVE-2024-41861 | MEDIUM | 5.5 | 0.2% | Aug 14, 2024 | Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to di... |
| CVE-2024-41860 | MEDIUM | 5.5 | 0.2% | Aug 14, 2024 | Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to di... |
| CVE-2024-41858 | HIGH | 7.8 | 0.3% | Aug 14, 2024 | InCopy versions 18.5.2, 19.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could resu... |
| CVE-2024-7732 | CRITICAL | 9.8 | 0.9% | Aug 14, 2024 | Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated re... |
| CVE-2024-7731 | CRITICAL | 9.8 | 0.8% | Aug 14, 2024 | Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated re... |
| CVE-2024-7588 | MEDIUM | 6.4 | 0.3% | Aug 14, 2024 | The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2024-7729 | HIGH | 7.5 | 0.6% | Aug 14, 2024 | The CAYIN Technology CMS lacks proper access control, allowing unauthenticated remote attackers to download arbitrary CG... |
| CVE-2024-7728 | HIGH | 7.2 | 0.7% | Aug 14, 2024 | The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with admi... |
| CVE-2024-38653 | HIGH | 7.5 | 92.0% | Aug 14, 2024 | XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on t... |
| CVE-2024-38652 | CRITICAL | 9.1 | 7.6% | Aug 14, 2024 | Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to ac... |
| CVE-2024-37399 | HIGH | 7.5 | 27.8% | Aug 14, 2024 | A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to c... |
| CVE-2024-37373 | HIGH | 7.2 | 1.6% | Aug 14, 2024 | Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with... |
| CVE-2024-36136 | HIGH | 7.5 | 2.2% | Aug 14, 2024 | An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the... |
| CVE-2024-20083 | CRITICAL | 9.8 | 0.3% | Aug 14, 2024 | In venc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p... |
| CVE-2024-20082 | CRITICAL | 9.8 | 1.4% | Aug 14, 2024 | In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote code execution ... |
| CVE-2024-7754 | HIGH | 7.5 | 0.5% | Aug 14, 2024 | A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. This i... |
| CVE-2024-7753 | HIGH | 7.5 | 0.9% | Aug 14, 2024 | A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as problematic. ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now