2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38360 | MEDIUM | 4.9 | 0.5% | Jul 15, 2024 | Discourse is an open source platform for community discussion. In affected versions by creating replacement words with a... |
| CVE-2024-40631 | HIGH | 8.1 | 0.5% | Jul 15, 2024 | Plate media is an open source, rich-text editor for React. Editors that use `MediaEmbedElement` and pass custom `urlPars... |
| CVE-2024-37386 | MEDIUM | 4.2 | 0.2% | Jul 15, 2024 | An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Cert... |
| CVE-2024-36438 | HIGH | 7.3 | 0.2% | Jul 15, 2024 | eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check... |
| CVE-2024-36434 | HIGH | 7.5 | 0.2% | Jul 15, 2024 | An SMM callout vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmw... |
| CVE-2024-36433 | HIGH | 7.5 | 0.2% | Jul 15, 2024 | An arbitrary memory write vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with... |
| CVE-2024-36432 | HIGH | 7.5 | 0.2% | Jul 15, 2024 | An arbitrary memory write vulnerability was discovered in Supermicro X11DPG-HGX2, X11PDG-QT, X11PDG-OT, and X11PDG-SN mo... |
| CVE-2024-31946 | MEDIUM | 4.2 | 0.2% | Jul 15, 2024 | An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through ... |
| CVE-2024-40416 | CRITICAL | 9.8 | 0.6% | Jul 15, 2024 | A vulnerability in /goform/SetVirtualServerCfg in the sub_6320C function in Tenda AX1806 1.0.0.1 firmware leads to stack... |
| CVE-2024-40415 | CRITICAL | 9.8 | 0.5% | Jul 15, 2024 | A vulnerability in /goform/SetStaticRouteCfg in the sub_519F4 function in Tenda AX1806 1.0.0.1 firmware leads to stack-b... |
| CVE-2024-39827 | MEDIUM | 5.5 | 0.2% | Jul 15, 2024 | Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an... |
| CVE-2024-39826 | MEDIUM | 6.8 | 0.4% | Jul 15, 2024 | Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct... |
| CVE-2024-39821 | MEDIUM | 4.4 | 0.1% | Jul 15, 2024 | Race condition in the installer for Zoom Workplace App for Windows and Zoom Rooms App for Windows may allow an authentic... |
| CVE-2024-39820 | MEDIUM | 5 | 0.2% | Jul 15, 2024 | Uncontrolled search path element in the installer for Zoom Workplace Desktop App for macOS before version 6.0.10 may all... |
| CVE-2024-39819 | HIGH | 7.3 | 0.1% | Jul 15, 2024 | Integrity check in the installer for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to co... |
| CVE-2024-37016 | MEDIUM | 6.8 | 0.3% | Jul 15, 2024 | Mengshen Wireless Door Alarm M70 2024-05-24 allows Authentication Bypass via a Capture-Replay approach. |
| CVE-2024-27241 | HIGH | 7.5 | 0.4% | Jul 15, 2024 | Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via ... |
| CVE-2024-27240 | HIGH | 7.8 | 0.2% | Jul 15, 2024 | Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a p... |
| CVE-2024-27238 | MEDIUM | 6.3 | 0.1% | Jul 15, 2024 | Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated ... |
| CVE-2024-40414 | CRITICAL | 9.8 | 0.5% | Jul 15, 2024 | A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmware leads to stack-b... |
| CVE-2024-40560 | HIGH | 7.3 | 0.3% | Jul 15, 2024 | Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability. |
| CVE-2024-40555 | MEDIUM | 5.3 | 0.3% | Jul 15, 2024 | Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability. |
| CVE-2024-40554 | HIGH | 7.5 | 0.4% | Jul 15, 2024 | An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information. |
| CVE-2024-40553 | MEDIUM | 4.9 | 0.3% | Jul 15, 2024 | Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage. |
| CVE-2024-6716 | — | — | — | Jul 15, 2024 | Rejected reason: Invalid security issue. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now