2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6645 | MEDIUM | 6.3 | 0.5% | Jul 10, 2024 | A vulnerability was found in WuKongOpenSource Wukong_nocode up to 20230807. It has been declared as critical. Affected b... |
| CVE-2024-6644 | MEDIUM | 6.3 | 0.5% | Jul 10, 2024 | A vulnerability was found in zmops ArgusDBM up to 0.1.0. It has been classified as critical. Affected is the function ge... |
| CVE-2024-5217 | CRITICAL | 9.8 | 99.6% | Jul 10, 2024 | ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earl... |
| CVE-2024-5178 | MEDIUM | 6.9 | 33.6% | Jul 10, 2024 | ServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Ut... |
| CVE-2024-4879 | CRITICAL | 9.8 | 100.0% | Jul 10, 2024 | ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platfo... |
| CVE-2024-3325 | HIGH | 7.2 | 0.6% | Jul 10, 2024 | Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0. |
| CVE-2024-40417 | MEDIUM | 6.5 | 0.4% | Jul 10, 2024 | A vulnerability was found in Tenda AX1806 1.0.0.1. Affected by this issue is the function formSetRebootTimer of the file... |
| CVE-2024-40412 | MEDIUM | 6.8 | 0.3% | Jul 10, 2024 | Tenda AX12 v1.0 v22.03.01.46 contains a stack overflow in the deviceList parameter of the sub_42E410 function. |
| CVE-2024-20456 | MEDIUM | 6.7 | 0.2% | Jul 10, 2024 | A vulnerability in the boot process of Cisco IOS XR Software could allow an authenticated, local attacker with high priv... |
| CVE-2024-40336 | MEDIUM | 6.1 | 0.4% | Jul 10, 2024 | idccms v1.35 is vulnerable to Cross Site Scripting (XSS) within the 'Image Advertising Management.' |
| CVE-2024-40332 | HIGH | 8.8 | 0.2% | Jul 10, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/moneyRecord_deal.php... |
| CVE-2024-40331 | HIGH | 8.8 | 0.3% | Jul 10, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/dbBakMySQL_deal.php?... |
| CVE-2024-6642 | — | — | — | Jul 10, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2024-40334 | HIGH | 8.8 | 0.3% | Jul 10, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/serverFile_deal.php?... |
| CVE-2024-40333 | HIGH | 8.8 | 0.6% | Jul 10, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mud... |
| CVE-2024-40329 | HIGH | 8.8 | 0.3% | Jul 10, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mud... |
| CVE-2024-40328 | MEDIUM | 6.3 | 0.2% | Jul 10, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/memberOnline_deal.ph... |
| CVE-2024-28828 | HIGH | 8.8 | 0.2% | Jul 10, 2024 | Cross-Site request forgery in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) could lead to 1-click com... |
| CVE-2024-28827 | HIGH | 7.8 | 0.2% | Jul 10, 2024 | Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <=... |
| CVE-2024-3799 | HIGH | 8.7 | 14.6% | Jul 10, 2024 | Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source projec... |
| CVE-2024-3798 | HIGH | 8.7 | 0.5% | Jul 10, 2024 | Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project... |
| CVE-2024-6556 | MEDIUM | 5.3 | 0.4% | Jul 10, 2024 | The SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer plugin for WordPress is vulnerable to Full Path Disclo... |
| CVE-2024-6422 | CRITICAL | 9.8 | 0.6% | Jul 10, 2024 | An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data. |
| CVE-2024-6421 | HIGH | 7.5 | 0.5% | Jul 10, 2024 | An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP servic... |
| CVE-2024-5664 | MEDIUM | 5.4 | 0.3% | Jul 10, 2024 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now