2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-40394 | CRITICAL | 9.8 | 0.7% | Jul 16, 2024 | Simple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnera... |
| CVE-2024-40393 | CRITICAL | 9.8 | 0.6% | Jul 16, 2024 | Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerabilit... |
| CVE-2024-40392 | CRITICAL | 9.8 | 0.5% | Jul 16, 2024 | SourceCodester Pharmacy/Medical Store Point of Sale System Using PHP/MySQL and Bootstrap Framework with Source Code 1.0 ... |
| CVE-2024-40130 | CRITICAL | 9.8 | 0.6% | Jul 16, 2024 | open5gs v2.6.4 is vulnerable to Buffer Overflow. via /lib/core/abts.c. |
| CVE-2024-40129 | CRITICAL | 9.8 | 0.5% | Jul 16, 2024 | Open5GS v2.6.4 is vulnerable to Buffer Overflow. via /lib/pfcp/context.c. |
| CVE-2024-39036 | MEDIUM | 6.5 | 0.6% | Jul 16, 2024 | SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php. |
| CVE-2024-40425 | CRITICAL | 9.8 | 0.7% | Jul 16, 2024 | File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a ... |
| CVE-2024-39908 | MEDIUM | 4.3 | 1.5% | Jul 16, 2024 | REXML is an XML toolkit for Ruby. The REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that ha... |
| CVE-2024-39700 | CRITICAL | 9.8 | 1.0% | Jul 16, 2024 | JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this templat... |
| CVE-2024-33181 | HIGH | 8.8 | 0.6% | Jul 16, 2024 | Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceMac parame... |
| CVE-2024-6326 | MEDIUM | 5.5 | 0.2% | Jul 16, 2024 | An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A mali... |
| CVE-2024-6325 | MEDIUM | 6.5 | 0.3% | Jul 16, 2024 | The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/e... |
| CVE-2024-6089 | HIGH | 7.5 | 2.1% | Jul 16, 2024 | An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent... |
| CVE-2024-40626 | MEDIUM | 5.4 | 0.5% | Jul 16, 2024 | Outline is an open source, collaborative document editor. A type confusion issue was found in ProseMirror’s rendering pr... |
| CVE-2024-3232 | MEDIUM | 6.8 | 0.5% | Jul 16, 2024 | A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with admini... |
| CVE-2024-40322 | HIGH | 8.8 | 0.4% | Jul 16, 2024 | An issue was discovered in JFinalCMS v.5.0.0. There is a SQL injection vulnerablity via /admin/div_data/data |
| CVE-2024-35338 | CRITICAL | 9.8 | 0.5% | Jul 16, 2024 | Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root. |
| CVE-2024-33182 | CRITICAL | 9.8 | 0.6% | Jul 16, 2024 | Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId paramet... |
| CVE-2024-33180 | CRITICAL | 9.8 | 0.6% | Jul 16, 2024 | Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId paramet... |
| CVE-2024-22442 | CRITICAL | 9.8 | 0.6% | Jul 16, 2024 | The vulnerability could be remotely exploited to bypass authentication. |
| CVE-2024-6655 | HIGH | 7 | 0.5% | Jul 16, 2024 | A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK ap... |
| CVE-2024-32861 | HIGH | 7.8 | 0.1% | Jul 16, 2024 | Under certain circumstances the impacted Software House C•CURE 9000 installer will utilize unnecessarily wide permission... |
| CVE-2024-6435 | HIGH | 8.8 | 0.5% | Jul 16, 2024 | A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privi... |
| CVE-2024-6621 | MEDIUM | 4.3 | 0.4% | Jul 16, 2024 | The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauth... |
| CVE-2024-6457 | HIGH | 7.5 | 19.7% | Jul 16, 2024 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now