2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39173 | CRITICAL | 9.8 | 0.8% | Jul 18, 2024 | calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function ... |
| CVE-2024-39090 | MEDIUM | 6.1 | 0.5% | Jul 18, 2024 | The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forger... |
| CVE-2024-30126 | MEDIUM | 4.7 | 0.2% | Jul 18, 2024 | HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malic... |
| CVE-2024-5321 | MEDIUM | 6.1 | 0.3% | Jul 18, 2024 | A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read contai... |
| CVE-2024-39152 | — | — | — | Jul 18, 2024 | Rejected reason: DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2024-6655. Reason: This record is a reservation duplicate ... |
| CVE-2024-38806 | LOW | 3.9 | 0.1% | Jul 18, 2024 | Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloud... |
| CVE-2024-5625 | MEDIUM | 6.5 | 0.4% | Jul 18, 2024 | Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console... |
| CVE-2024-30125 | MEDIUM | 6.2 | 0.1% | Jul 18, 2024 | HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the s... |
| CVE-2024-0857 | CRITICAL | 9.8 | 0.4% | Jul 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software... |
| CVE-2024-5620 | MEDIUM | 6.5 | 0.3% | Jul 18, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in PruvaSoft Informatics Apinizer Management Cons... |
| CVE-2024-5619 | CRITICAL | 9.6 | 0.4% | Jul 18, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allo... |
| CVE-2024-5618 | CRITICAL | 9.9 | 0.4% | Jul 18, 2024 | Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console... |
| CVE-2024-40648 | MEDIUM | 5.4 | 0.3% | Jul 18, 2024 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method... |
| CVE-2024-40647 | MEDIUM | 5.3 | 0.2% | Jul 18, 2024 | sentry-sdk is the official Python SDK for Sentry.io. A bug in Sentry's Python SDK < 2.8.0 allows the environment variabl... |
| CVE-2024-40644 | MEDIUM | 6.8 | 0.2% | Jul 18, 2024 | gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another... |
| CVE-2024-40629 | CRITICAL | 9.8 | 1.3% | Jul 18, 2024 | JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand an... |
| CVE-2024-40628 | CRITICAL | 9.1 | 0.9% | Jul 18, 2024 | JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand an... |
| CVE-2024-39911 | CRITICAL | 9.8 | 4.6% | Jul 18, 2024 | 1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent... |
| CVE-2024-39907 | CRITICAL | 9.8 | 29.4% | Jul 18, 2024 | 1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of t... |
| CVE-2024-38302 | MEDIUM | 5.7 | 0.1% | Jul 18, 2024 | Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in the DDAE (St... |
| CVE-2024-30473 | MEDIUM | 6.5 | 0.3% | Jul 18, 2024 | Dell ECS, versions prior to 3.8.1, contain a privilege elevation vulnerability in user management. A remote high privile... |
| CVE-2024-34013 | HIGH | 7.8 | 0.6% | Jul 18, 2024 | Local privilege escalation due to OS command injection vulnerability. The following products are affected: Acronis True ... |
| CVE-2024-31143 | HIGH | 7.5 | 0.5% | Jul 18, 2024 | An optional feature of PCI MSI called "Multiple Message" allows a device to use multiple consecutive interrupt vectors. ... |
| CVE-2024-29178 | HIGH | 8.8 | 1.2% | Jul 18, 2024 | On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution... |
| CVE-2024-6504 | MEDIUM | 5.3 | 0.3% | Jul 18, 2024 | Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with netw... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now