2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5013 | HIGH | 7.5 | 0.8% | Jun 25, 2024 | In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Denial of Service vulnerability was identified. ... |
| CVE-2024-5012 | HIGH | 8.6 | 0.4% | Jun 25, 2024 | In WhatsUp Gold versions released before 2023.1.3, there is a missing authentication vulnerability in WUGDataAccess.Cred... |
| CVE-2024-38516 | HIGH | 8.8 | 0.5% | Jun 25, 2024 | ai-client-html is an Aimeos e-commerce HTML client component. Debug information revealed sensitive information from envi... |
| CVE-2024-37855 | HIGH | 8.4 | 0.5% | Jun 25, 2024 | An issue in Nepstech Wifi Router xpon (terminal) NTPL-Xpon1GFEVN, hardware verstion 1.0 firmware 2.0.1 allows a remote a... |
| CVE-2024-37843 | CRITICAL | 9.8 | 51.3% | Jun 25, 2024 | Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint. |
| CVE-2024-35526 | MEDIUM | 5.9 | 0.2% | Jun 25, 2024 | An issue in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to access sensitive information in t... |
| CVE-2024-34400 | MEDIUM | 6.1 | 0.3% | Jun 25, 2024 | An issue was discovered in VirtoSoftware Virto Kanban Board Web Part before 5.3.5.1 for SharePoint 2019. There is /_layo... |
| CVE-2024-21741 | CRITICAL | 9.8 | 0.4% | Jun 25, 2024 | GigaDevice GD32E103C8T6 devices have Incorrect Access Control. |
| CVE-2024-21740 | HIGH | 7.4 | 0.1% | Jun 25, 2024 | Artery AT32F415CBT7 and AT32F421C8T7 devices have Incorrect Access Control. |
| CVE-2024-21739 | MEDIUM | 5.3 | 0.3% | Jun 25, 2024 | Geehy APM32F103CCT6, APM32F103RCT6, APM32F103RCT7, and APM32F103VCT6 devices have Incorrect Access Control. |
| CVE-2024-6206 | HIGH | 7.5 | 0.4% | Jun 25, 2024 | A security vulnerability has been identified in HPE Athonet Mobile Core software. The core application contains a code i... |
| CVE-2024-5276 | CRITICAL | 9.1 | 90.1% | Jun 25, 2024 | A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data. Likely imp... |
| CVE-2024-5011 | HIGH | 7.5 | 47.1% | Jun 25, 2024 | In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerability exists. A speciall... |
| CVE-2024-5010 | HIGH | 7.5 | 70.0% | Jun 25, 2024 | In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController functionality. A specia... |
| CVE-2024-5009 | HIGH | 8.4 | 15.0% | Jun 25, 2024 | In WhatsUp Gold versions released before 2023.1.3, an Improper Access Control vulnerability in Wug.UI.Controllers.Instal... |
| CVE-2024-5008 | HIGH | 8.8 | 17.3% | Jun 25, 2024 | In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions can upload an arbitr... |
| CVE-2024-4885 | CRITICAL | 9.8 | 99.3% | Jun 25, 2024 | In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress Wh... |
| CVE-2024-4884 | CRITICAL | 9.8 | 24.3% | Jun 25, 2024 | In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress Wh... |
| CVE-2024-4883 | CRITICAL | 9.8 | 64.8% | Jun 25, 2024 | In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This v... |
| CVE-2024-4498 | HIGH | 7.7 | 0.5% | Jun 25, 2024 | A Path Traversal and Remote File Inclusion (RFI) vulnerability exists in the parisneo/lollms-webui application, affectin... |
| CVE-2024-37894 | MEDIUM | 6.3 | 6.3% | Jun 25, 2024 | Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when ass... |
| CVE-2024-37167 | MEDIUM | 4.3 | 0.4% | Jun 25, 2024 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see b... |
| CVE-2024-37820 | MEDIUM | 5.4 | 0.4% | Jun 25, 2024 | A nil pointer dereference in PingCAP TiDB v8.2.0-alpha-216-gfe5858b allows attackers to crash the application via expres... |
| CVE-2024-36819 | MEDIUM | 5.4 | 0.3% | Jun 25, 2024 | MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to inse... |
| CVE-2024-6308 | CRITICAL | 9.8 | 0.7% | Jun 25, 2024 | A vulnerability was found in itsourcecode Simple Online Hotel Reservation System 1.0. It has been declared as critical. ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now