2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41354 | HIGH | 7.1 | 0.3% | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php |
| CVE-2024-41353 | HIGH | 7.1 | 0.3% | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php |
| CVE-2024-27358 | LOW | 3.3 | 0.2% | Jul 26, 2024 | An issue was discovered in WithSecure Elements Agent through 23.x for macOS and WithSecure Elements Client Security thro... |
| CVE-2024-27357 | MEDIUM | 5.8 | 0.2% | Jul 26, 2024 | An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through... |
| CVE-2024-26520 | CRITICAL | 9.8 | 0.5% | Jul 26, 2024 | An issue in Hangzhou Xiongwei Technology Development Co., Ltd. Restaurant Digital Comprehensive Management platform v1 a... |
| CVE-2024-24257 | HIGH | 7.5 | 0.4% | Jul 26, 2024 | An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sen... |
| CVE-2024-7050 | HIGH | 8.3 | 0.6% | Jul 26, 2024 | Improper Authentication vulnerability in OpenText OpenText Directory Services may allow Multi-factor Authentication Bypa... |
| CVE-2024-41807 | — | — | — | Jul 26, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2023-4759. Reason: This record is a reservati... |
| CVE-2024-41357 | HIGH | 7.1 | 1.1% | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php. |
| CVE-2024-41356 | MEDIUM | 4.7 | 0.4% | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\firewall-zones\zones-edit-network.php. |
| CVE-2024-41355 | MEDIUM | 6.5 | 0.4% | Jul 26, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php. |
| CVE-2024-41805 | MEDIUM | 6.1 | 0.4% | Jul 26, 2024 | Tracks, a Getting Things Done (GTD) web application, is vulnerable to reflected cross-site scripting in versions prior t... |
| CVE-2024-41670 | HIGH | 7.5 | 0.4% | Jul 26, 2024 | In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior ... |
| CVE-2024-7128 | MEDIUM | 5.3 | 0.4% | Jul 26, 2024 | A flaw was found in the OpenShift console. Several endpoints in the application use the authHandler() and authHandlerWit... |
| CVE-2024-6922 | MEDIUM | 6.9 | 30.2% | Jul 26, 2024 | Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web API component. An attac... |
| CVE-2024-40689 | CRITICAL | 9.8 | 0.5% | Jul 26, 2024 | IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ... |
| CVE-2024-41692 | HIGH | 8.6 | 0.3% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to presence of root terminal access on a serial inte... |
| CVE-2024-7062 | HIGH | 7.8 | 0.2% | Jul 26, 2024 | Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.Privileged... |
| CVE-2024-41691 | MEDIUM | 4.6 | 0.2% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of FTP credentials in plaintext within th... |
| CVE-2024-41690 | MEDIUM | 4.6 | 0.2% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to storing of default username and password credenti... |
| CVE-2024-41689 | MEDIUM | 4.6 | 0.2% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA/ WPS credentials withi... |
| CVE-2024-41688 | MEDIUM | 4.6 | 0.1% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due lack of encryption in storing of usernames and passw... |
| CVE-2024-41687 | HIGH | 7.5 | 0.3% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote ... |
| CVE-2024-41686 | LOW | 3.3 | 0.2% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password policies. A l... |
| CVE-2024-41685 | HIGH | 7.5 | 0.5% | Jul 26, 2024 | This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies ass... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now