2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38301 | HIGH | 7.8 | 0.1% | Jul 10, 2024 | Dell Alienware Command Center, version 5.7.3.0 and prior, contains an improper access control vulnerability. A low privi... |
| CVE-2024-5792 | HIGH | 8.8 | 0.5% | Jul 10, 2024 | The Houzez CRM plugin for WordPress is vulnerable to time-based SQL Injection via the notes ‘belong_to’ parameter in all... |
| CVE-2024-5677 | MEDIUM | 4.3 | 0.3% | Jul 10, 2024 | The Featured Image Generator plugin for WordPress is vulnerable to unauthorized image upload due to a missing capability... |
| CVE-2024-4866 | MEDIUM | 5.4 | 0.4% | Jul 10, 2024 | The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere El... |
| CVE-2024-22018 | LOW | 2.9 | 0.5% | Jul 10, 2024 | A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs... |
| CVE-2024-6433 | HIGH | 7.5 | 0.6% | Jul 10, 2024 | The application zips all the files in the folder specified by the user, which allows an attacker to read arbitrary files... |
| CVE-2024-32670 | HIGH | 7 | 0.2% | Jul 10, 2024 | Exposure of Sensitive Information to an Unauthorized Actor in Samsung Galaxy SmartTag2 prior to 0.20.04 allows attackes ... |
| CVE-2024-25023 | MEDIUM | 5.5 | 0.1% | Jul 10, 2024 | IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores p... |
| CVE-2024-21417 | HIGH | 8.8 | 0.4% | Jul 10, 2024 | Windows Text Services Framework Elevation of Privilege Vulnerability |
| CVE-2024-22477 | MEDIUM | 4.3 | 0.2% | Jul 9, 2024 | A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained ... |
| CVE-2024-22377 | MEDIUM | 5.3 | 0.4% | Jul 9, 2024 | The deploy directory in PingFederate runtime nodes is reachable to unauthorized users. |
| CVE-2024-21832 | LOW | 3.5 | 0.2% | Jul 9, 2024 | A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON re... |
| CVE-2024-39901 | MEDIUM | 5.4 | 0.3% | Jul 9, 2024 | OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the Op... |
| CVE-2024-39900 | MEDIUM | 5.4 | 0.3% | Jul 9, 2024 | OpenSearch Dashboards Reports allows ‘Report Owner’ export and share reports from OpenSearch Dashboards. An issue in the... |
| CVE-2024-39883 | HIGH | 8.8 | 0.7% | Jul 9, 2024 | Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-... |
| CVE-2024-39882 | HIGH | 8.8 | 0.7% | Jul 9, 2024 | Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of a... |
| CVE-2024-39881 | HIGH | 8.8 | 0.7% | Jul 9, 2024 | Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a memory corruption cond... |
| CVE-2024-39880 | HIGH | 8.8 | 0.7% | Jul 9, 2024 | Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-... |
| CVE-2024-39069 | HIGH | 7.8 | 0.6% | Jul 9, 2024 | An issue in ifood Order Manager v3.35.5 'Gestor de Peddios.exe' allows attackers to execute arbitrary code via a DLL hij... |
| CVE-2024-38963 | MEDIUM | 6.1 | 0.3% | Jul 9, 2024 | Nopcommerce 4.70.1 is vulnerable to Cross Site Scripting (XSS) via the combined "AddProductReview.Title" and "AddProduct... |
| CVE-2024-36676 | HIGH | 7.5 | 0.6% | Jul 9, 2024 | Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targ... |
| CVE-2024-35154 | HIGH | 7.2 | 1.2% | Jul 9, 2024 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote authenticated attacker, who has authorized access to t... |
| CVE-2024-21993 | MEDIUM | 6.5 | 0.2% | Jul 9, 2024 | SnapCenter versions prior to 5.0p1 are susceptible to a vulnerability which could allow an authenticated attacker to di... |
| CVE-2024-39181 | MEDIUM | 6.5 | 0.5% | Jul 9, 2024 | Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a buffer overflow via the ApCliSsid pa... |
| CVE-2024-39072 | MEDIUM | 5.5 | 0.4% | Jul 9, 2024 | AMTT Hotel Broadband Operation System (HiBOS) v3.0.3.151204 is vulnerable to SQL injection via manager/conference/calend... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now