2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6306 | — | — | — | Jun 25, 2024 | Rejected reason: **REJECT** Accidental Reservation making this a duplicate. Please use CVE-2024-32111. |
| CVE-2024-6305 | — | — | — | Jun 25, 2024 | Rejected reason: **REJECT** Accidental Reservation making this a duplicate. Please use CVE-2024-31111. |
| CVE-2024-5216 | HIGH | 7.5 | 0.6% | Jun 25, 2024 | A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resourc... |
| CVE-2024-4641 | CRITICAL | 9.8 | 0.3% | Jun 25, 2024 | OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format... |
| CVE-2024-4640 | HIGH | 8.2 | 0.4% | Jun 25, 2024 | OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to missing bounds che... |
| CVE-2024-4639 | HIGH | 8.8 | 0.4% | Jun 25, 2024 | OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutrali... |
| CVE-2024-6028 | CRITICAL | 9.8 | 11.8% | Jun 25, 2024 | The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all v... |
| CVE-2024-4638 | HIGH | 8.8 | 0.4% | Jun 25, 2024 | OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutrali... |
| CVE-2024-34142 | MEDIUM | 5.4 | 0.3% | Jun 25, 2024 | Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-34141 | MEDIUM | 5.4 | 0.3% | Jun 25, 2024 | Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-3249 | MEDIUM | 4.3 | 0.3% | Jun 25, 2024 | The Zita Elementor Site Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... |
| CVE-2024-5431 | HIGH | 8.8 | 0.6% | Jun 25, 2024 | The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is v... |
| CVE-2024-4759 | MEDIUM | 5.5 | 0.4% | Jun 25, 2024 | The Mime Types Extended WordPress plugin through 0.11 does not sanitise uploaded SVG files, which could allow users with... |
| CVE-2024-4757 | HIGH | 8.1 | 0.5% | Jun 25, 2024 | The Logo Manager For Enamad WordPress plugin through 0.7.0 does not have CSRF check in some places, and is missing sanit... |
| CVE-2024-6297 | CRITICAL | 10 | 1.0% | Jun 25, 2024 | Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A m... |
| CVE-2024-4197 | CRITICAL | 9.8 | 0.8% | Jun 25, 2024 | An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code exec... |
| CVE-2024-4196 | CRITICAL | 9.8 | 0.6% | Jun 25, 2024 | An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code ex... |
| CVE-2024-37007 | HIGH | 7.8 | 0.4% | Jun 25, 2024 | A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can cause a use-after... |
| CVE-2024-37006 | HIGH | 7.8 | 0.4% | Jun 25, 2024 | A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory cor... |
| CVE-2024-37005 | HIGH | 7.8 | 0.4% | Jun 25, 2024 | A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can force an Out-of-Bound Rea... |
| CVE-2024-37004 | HIGH | 7.8 | 0.4% | Jun 25, 2024 | A maliciously crafted SLDPRT file, when parsed in ASMKERN229A.dll through Autodesk applications, can cause a use-after-f... |
| CVE-2024-37003 | HIGH | 7.8 | 0.3% | Jun 25, 2024 | A maliciously crafted DWG and SLDPRT file, when parsed in opennurbs.dll and ODXSW_DLL.dll through Autodesk applications,... |
| CVE-2024-36999 | HIGH | 7.8 | 0.4% | Jun 25, 2024 | A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds W... |
| CVE-2024-32855 | MEDIUM | 4.4 | 0.1% | Jun 25, 2024 | Dell Client Platform BIOS contains an Out-of-bounds Write vulnerability in an externally developed component. A high pri... |
| CVE-2024-23159 | HIGH | 7.8 | 0.3% | Jun 25, 2024 | A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to unini... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now