2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38496 | MEDIUM | 5.1 | 0.3% | Jul 15, 2024 | The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group... |
| CVE-2024-38495 | MEDIUM | 5.3 | 0.3% | Jul 15, 2024 | A specific authentication strategy allows a malicious attacker to learn ids of all PAM users defined in its database. |
| CVE-2024-6689 | HIGH | 7.8 | 0.2% | Jul 15, 2024 | Local Privilege Escalation in MSI-Installer in baramundi Management Agent v23.1.172.0 on Windows allows a local unprivil... |
| CVE-2024-38494 | HIGH | 8.6 | 0.6% | Jul 15, 2024 | This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected P... |
| CVE-2024-38493 | MEDIUM | 6.1 | 0.3% | Jul 15, 2024 | A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convi... |
| CVE-2024-38492 | CRITICAL | 9.4 | 0.9% | Jul 15, 2024 | This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by ... |
| CVE-2024-38491 | HIGH | 8.4 | 0.3% | Jul 15, 2024 | The vulnerability allows an unauthenticated attacker to read arbitrary information from the database. |
| CVE-2024-36458 | MEDIUM | 5.1 | 0.2% | Jul 15, 2024 | The vulnerability allows a malicious low-privileged PAM user to perform server upgrade related actions. |
| CVE-2024-36457 | MEDIUM | 5.3 | 0.3% | Jul 15, 2024 | The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint. |
| CVE-2024-36456 | CRITICAL | 9.4 | 0.9% | Jul 15, 2024 | This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by ... |
| CVE-2024-36455 | CRITICAL | 9.4 | 0.5% | Jul 15, 2024 | An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM ... |
| CVE-2024-6721 | — | — | — | Jul 15, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2024-5324. Reason: This record is a reservat... |
| CVE-2024-6746 | HIGH | 8.8 | 3.3% | Jul 15, 2024 | A vulnerability classified as problematic was found in NaiboWang EasySpider 0.6.2 on Windows. Affected by this vulnerabi... |
| CVE-2024-5402 | HIGH | 7.8 | 0.2% | Jul 15, 2024 | Unquoted Search Path or Element vulnerability in ABB Mint Workbench. A local attacker who successfully exploited this... |
| CVE-2024-6745 | CRITICAL | 9.8 | 0.7% | Jul 15, 2024 | A vulnerability classified as critical has been found in code-projects Simple Ticket Booking 1.0. Affected is an unknown... |
| CVE-2024-6741 | MEDIUM | 5.3 | 0.6% | Jul 15, 2024 | Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers c... |
| CVE-2024-6398 | MEDIUM | 5.3 | 0.3% | Jul 15, 2024 | An information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows inform... |
| CVE-2024-41007 | LOW | 3.3 | 0.2% | Jul 15, 2024 | In the Linux kernel, the following vulnerability has been resolved: tcp: avoid too many retransmit packets If a TCP so... |
| CVE-2024-39767 | MEDIUM | 6.5 | 0.2% | Jul 15, 2024 | Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually cam... |
| CVE-2024-32945 | MEDIUM | 5.3 | 0.2% | Jul 15, 2024 | Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows a... |
| CVE-2024-6740 | MEDIUM | 6.1 | 0.5% | Jul 15, 2024 | Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject Jav... |
| CVE-2024-6540 | MEDIUM | 5.3 | 0.4% | Jul 15, 2024 | Improper filtering of fields when using the export function in the ticket overview of the external interface in OTRS cou... |
| CVE-2024-23794 | HIGH | 7.5 | 0.3% | Jul 15, 2024 | An incorrect privilege assignment vulnerability in the inline editing functionality of OTRS can lead to privilege escala... |
| CVE-2024-6744 | CRITICAL | 9.8 | 0.8% | Jul 15, 2024 | The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Ove... |
| CVE-2024-6743 | CRITICAL | 9.8 | 0.7% | Jul 15, 2024 | AguardNet's Space Management System does not properly validate user input, allowing unauthenticated remote attackers to ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now