2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36541 | HIGH | 8.8 | 0.4% | Jul 24, 2024 | Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obt... |
| CVE-2024-31970 | HIGH | 8.8 | 0.6% | Jul 24, 2024 | AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have SSH enabled by default... |
| CVE-2024-22444 | MEDIUM | 6.1 | 0.3% | Jul 24, 2024 | A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attack... |
| CVE-2024-7068 | MEDIUM | 4.6 | 0.4% | Jul 24, 2024 | A vulnerability classified as problematic has been found in SourceCodester Insurance Management System 1.0. This affects... |
| CVE-2024-41914 | CRITICAL | 9 | 0.5% | Jul 24, 2024 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re... |
| CVE-2024-39345 | HIGH | 7.2 | 0.5% | Jul 24, 2024 | AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented,... |
| CVE-2024-31977 | HIGH | 8.8 | 1.7% | Jul 24, 2024 | Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via s... |
| CVE-2024-31971 | MEDIUM | 4.8 | 0.4% | Jul 24, 2024 | Multiple stored cross-site scripting (XSS) vulnerabilities on AdTran NetVanta 3120 18.01.01.00.E devices allow remote at... |
| CVE-2024-22443 | HIGH | 8.8 | 0.8% | Jul 24, 2024 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re... |
| CVE-2024-7067 | HIGH | 8.8 | 0.8% | Jul 24, 2024 | A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87. It ... |
| CVE-2024-6327 | CRITICAL | 9.8 | 2.0% | Jul 24, 2024 | In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible ... |
| CVE-2024-6096 | CRITICAL | 9.8 | 0.9% | Jul 24, 2024 | In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object inject... |
| CVE-2024-5818 | MEDIUM | 5.4 | 0.2% | Jul 24, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via... |
| CVE-2024-3896 | MEDIUM | 5.4 | 0.2% | Jul 24, 2024 | The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-7066 | CRITICAL | 9.8 | 3.4% | Jul 24, 2024 | A vulnerability was found in F-logic DataCube3 1.0. It has been declared as critical. Affected by this vulnerability is ... |
| CVE-2024-6896 | MEDIUM | 5.4 | 0.3% | Jul 24, 2024 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File... |
| CVE-2024-7065 | MEDIUM | 4.3 | 0.3% | Jul 24, 2024 | A vulnerability was found in Spina CMS up to 2.18.0. It has been classified as problematic. Affected is an unknown funct... |
| CVE-2024-6930 | MEDIUM | 5.4 | 0.3% | Jul 24, 2024 | The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute withi... |
| CVE-2024-6874 | MEDIUM | 4.3 | 0.8% | Jul 24, 2024 | libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to... |
| CVE-2024-6197 | HIGH | 7.5 | 4.3% | Jul 24, 2024 | libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid fi... |
| CVE-2024-3454 | LOW | 3.5 | 0.2% | Jul 24, 2024 | An implementation issue in the Connectivity Standards Alliance Matter 1.2 protocol as used in the connectedhomeip SDK al... |
| CVE-2024-3297 | MEDIUM | 6.5 | 0.2% | Jul 24, 2024 | An issue in the Certificate Authenticated Session Establishment (CASE) protocol for establishing secure sessions between... |
| CVE-2024-39676 | HIGH | 7.5 | 0.8% | Jul 24, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pin... |
| CVE-2024-6629 | MEDIUM | 5.4 | 0.3% | Jul 24, 2024 | The All-in-One Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video sh... |
| CVE-2024-6571 | MEDIUM | 5.3 | 0.4% | Jul 24, 2024 | The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now