2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6742 | MEDIUM | 5.4 | 0.3% | Jul 15, 2024 | AguardNet Technology's Space Management System does not properly filter user input, allowing remote attackers with regul... |
| CVE-2024-6289 | MEDIUM | 6.1 | 0.9% | Jul 15, 2024 | The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect W... |
| CVE-2024-6076 | MEDIUM | 6.1 | 0.4% | Jul 15, 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputtin... |
| CVE-2024-6075 | HIGH | 8.8 | 0.4% | Jul 15, 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not have CSRF checks in some places, which could all... |
| CVE-2024-6074 | MEDIUM | 6.1 | 0.3% | Jul 15, 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputtin... |
| CVE-2024-6073 | MEDIUM | 6.1 | 0.3% | Jul 15, 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not sanitise and escape a parameter before outputtin... |
| CVE-2024-6072 | MEDIUM | 6.1 | 0.3% | Jul 15, 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.5 does not escape the $_SERVER['REQUEST_URI'] parameter bef... |
| CVE-2024-5630 | HIGH | 8.8 | 0.7% | Jul 15, 2024 | The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading... |
| CVE-2024-21513 | HIGH | 8.5 | 1.5% | Jul 15, 2024 | Versions of the package langchain-experimental from 0.0.15 and before 0.0.21 are vulnerable to Arbitrary Code Execution ... |
| CVE-2024-6739 | MEDIUM | 6.1 | 0.4% | Jul 15, 2024 | The session cookie in MailGates and MailAudit from Openfind does not have the HttpOnly flag enabled, allowing remote att... |
| CVE-2024-6738 | MEDIUM | 5.3 | 0.5% | Jul 15, 2024 | The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers t... |
| CVE-2024-6737 | HIGH | 8.8 | 0.6% | Jul 15, 2024 | The access control in the Electronic Official Document Management System from 2100 TECHNOLOGY is not properly implement... |
| CVE-2024-39741 | MEDIUM | 5.3 | 0.7% | Jul 15, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to traverse directories on the... |
| CVE-2024-39740 | MEDIUM | 5.3 | 0.4% | Jul 15, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 displays version information in HTTP requests that could all... |
| CVE-2024-39735 | MEDIUM | 5.4 | 0.3% | Jul 15, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability al... |
| CVE-2024-39729 | MEDIUM | 4.3 | 0.4% | Jul 15, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow an authenticated user to obtain sensitive inform... |
| CVE-2024-39739 | MEDIUM | 4.3 | 0.2% | Jul 15, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to server-side request forgery (SSRF). This ma... |
| CVE-2024-39737 | MEDIUM | 5.3 | 0.4% | Jul 15, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to obtain sensitive informatio... |
| CVE-2024-39736 | CRITICAL | 9.8 | 0.4% | Jul 15, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to HTTP header injection, caused by improper v... |
| CVE-2024-39731 | HIGH | 7.5 | 0.3% | Jul 15, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 uses weaker than expected cryptographic algorithms that coul... |
| CVE-2024-39728 | MEDIUM | 5.4 | 0.3% | Jul 15, 2024 | IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to stored cross-site scripting. This vulnerabi... |
| CVE-2024-6736 | HIGH | 8.8 | 0.5% | Jul 15, 2024 | A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been rated as crit... |
| CVE-2024-6345 | HIGH | 8.8 | 1.9% | Jul 15, 2024 | A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution vi... |
| CVE-2024-6735 | HIGH | 8.8 | 0.6% | Jul 15, 2024 | A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been declared as critical. This vulner... |
| CVE-2024-6734 | HIGH | 8.8 | 0.6% | Jul 15, 2024 | A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been classified as critical. This affe... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now