2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36683 | HIGH | 7.3 | 1.0% | Jun 24, 2024 | SQL injection vulnerability in the module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaSho... |
| CVE-2024-36681 | CRITICAL | 9.8 | 0.5% | Jun 24, 2024 | SQL Injection vulnerability in the module "Isotope" (pk_isotope) <=1.7.3 from Promokit.eu for PrestaShop allows attacker... |
| CVE-2024-34992 | HIGH | 8.8 | 0.4% | Jun 24, 2024 | SQL Injection vulnerability in the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.... |
| CVE-2024-34988 | CRITICAL | 9.8 | 0.4% | Jun 24, 2024 | SQL injection vulnerability in the module "Complete for Create a Quote in Frontend + Backend Pro" (askforaquotemodul) <=... |
| CVE-2024-22168 | MEDIUM | 5.9 | 0.3% | Jun 24, 2024 | A Cross-Site Scripting (XSS) vulnerability on the My Cloud, My Cloud Home, SanDisk ibi, and WD Cloud web apps was found ... |
| CVE-2024-6293 | HIGH | 8.8 | 0.5% | Jun 24, 2024 | Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap co... |
| CVE-2024-6292 | HIGH | 8.8 | 0.5% | Jun 24, 2024 | Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap co... |
| CVE-2024-6291 | HIGH | 8.8 | 0.5% | Jun 24, 2024 | Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit ... |
| CVE-2024-6290 | HIGH | 8.8 | 0.5% | Jun 24, 2024 | Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap co... |
| CVE-2024-36682 | HIGH | 7.5 | 0.4% | Jun 24, 2024 | In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all ema... |
| CVE-2024-34991 | HIGH | 7.5 | 0.4% | Jun 24, 2024 | In the module "Axepta" (axepta) before 1.3.4 from Quadra Informatique for PrestaShop, a guest can download partial credi... |
| CVE-2024-33898 | CRITICAL | 9.8 | 0.7% | Jun 24, 2024 | Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An ... |
| CVE-2024-38903 | MEDIUM | 4.1 | 0.4% | Jun 24, 2024 | H3C Magic R230 V100R002's udpserver opens port 9034, allowing attackers to execute arbitrary commands. |
| CVE-2024-38902 | CRITICAL | 9.8 | 0.5% | Jun 24, 2024 | H3C Magic R230 V100R002 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attack... |
| CVE-2024-38897 | MEDIUM | 5.3 | 0.4% | Jun 24, 2024 | WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information. |
| CVE-2024-38896 | MEDIUM | 5.3 | 1.2% | Jun 24, 2024 | WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi. |
| CVE-2024-38895 | MEDIUM | 5.3 | 0.4% | Jun 24, 2024 | WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information. |
| CVE-2024-38894 | MEDIUM | 5.3 | 1.2% | Jun 24, 2024 | WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi. |
| CVE-2024-38892 | MEDIUM | 6.5 | 0.4% | Jun 24, 2024 | An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh compon... |
| CVE-2024-37759 | CRITICAL | 9.8 | 2.8% | Jun 24, 2024 | DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerabi... |
| CVE-2024-37681 | MEDIUM | 6.5 | 0.5% | Jun 24, 2024 | An issue the background management system of Shanxi Internet Chuangxiang Technology Co., Ltd v1.0.1 allows a remote atta... |
| CVE-2024-37678 | MEDIUM | 5.3 | 0.3% | Jun 24, 2024 | Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows... |
| CVE-2024-34313 | CRITICAL | 9.8 | 1.5% | Jun 24, 2024 | An issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a pu... |
| CVE-2024-34312 | MEDIUM | 6.1 | 0.8% | Jun 24, 2024 | Virtual Programming Lab for Moodle up to v4.2.3 was discovered to contain a cross-site scripting (XSS) vulnerability via... |
| CVE-2024-37732 | MEDIUM | 6.1 | 16.0% | Jun 24, 2024 | Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a craft... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now