2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6342 | CRITICAL | 9.8 | 2.1% | Sep 10, 2024 | **UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versi... |
| CVE-2024-8611 | CRITICAL | 9.8 | 0.7% | Sep 9, 2024 | A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulne... |
| CVE-2024-44411 | CRITICAL | 9.8 | 3.7% | Sep 9, 2024 | D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function. |
| CVE-2024-44410 | CRITICAL | 9.8 | 3.2% | Sep 9, 2024 | D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function. |
| CVE-2024-6796 | CRITICAL | 9.1 | 0.4% | Sep 9, 2024 | In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that c... |
| CVE-2024-6795 | CRITICAL | 9.8 | 0.6% | Sep 9, 2024 | In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an un... |
| CVE-2024-44902 | CRITICAL | 9.8 | 4.3% | Sep 9, 2024 | A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code. |
| CVE-2024-42500 | CRITICAL | 9.3 | 0.4% | Sep 9, 2024 | HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services. |
| CVE-2024-44849 | CRITICAL | 9.8 | 46.3% | Sep 9, 2024 | Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php. |
| CVE-2024-44721 | CRITICAL | 9.8 | 0.6% | Sep 9, 2024 | SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php. |
| CVE-2024-40643 | CRITICAL | 9.6 | 0.7% | Sep 9, 2024 | Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by ... |
| CVE-2024-7015 | CRITICAL | 9.8 | 0.4% | Sep 9, 2024 | Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authent... |
| CVE-2024-8584 | CRITICAL | 9.8 | 0.7% | Sep 9, 2024 | Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to ... |
| CVE-2024-8579 | CRITICAL | 9.8 | 1.3% | Sep 8, 2024 | A vulnerability classified as critical has been found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This affects the func... |
| CVE-2024-8570 | CRITICAL | 9.8 | 0.6% | Sep 8, 2024 | A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this i... |
| CVE-2024-6928 | CRITICAL | 9.8 | 3.3% | Sep 8, 2024 | The Opti Marketing WordPress plugin through 2.0.9 does not properly sanitise and escape a parameter before using it in a... |
| CVE-2024-6924 | CRITICAL | 9.8 | 3.3% | Sep 8, 2024 | The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL... |
| CVE-2024-8569 | CRITICAL | 9.8 | 0.8% | Sep 8, 2024 | A vulnerability has been found in code-projects Hospital Management System 1.0 and classified as critical. Affected by t... |
| CVE-2024-8568 | CRITICAL | 9.8 | 0.5% | Sep 8, 2024 | A vulnerability, which was classified as critical, was found in Mini-Tmall up to 20240901. Affected is the function rewa... |
| CVE-2024-8567 | CRITICAL | 9.8 | 0.7% | Sep 8, 2024 | A vulnerability, which was classified as critical, has been found in itsourcecode Payroll Management System 1.0. This is... |
| CVE-2024-8565 | CRITICAL | 9.8 | 0.7% | Sep 7, 2024 | A vulnerability was found in SourceCodesters Clinics Patient Management System 2.0. It has been rated as critical. This ... |
| CVE-2024-8561 | CRITICAL | 9.8 | 0.4% | Sep 7, 2024 | A vulnerability has been found in SourceCodester PHP CRUD 1.0 and classified as critical. Affected by this vulnerability... |
| CVE-2024-40711 | CRITICAL | 9.8 | 88.2% | Sep 7, 2024 | A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code exec... |
| CVE-2024-39714 | CRITICAL | 9.9 | 1.2% | Sep 7, 2024 | A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to re... |
| CVE-2024-38650 | CRITICAL | 9.9 | 0.9% | Sep 7, 2024 | An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now