2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34027 | HIGH | 7.8 | 0.2% | Jun 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix to cover {reserve,release}_comp... |
| CVE-2024-33847 | MEDIUM | 5.5 | 0.2% | Jun 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: don't allow unaligned truncation on... |
| CVE-2024-33278 | CRITICAL | 9.8 | 0.8% | Jun 24, 2024 | Buffer Overflow vulnerability in ASUS router RT-AX88U with firmware versions v3.0.0.4.388_24198 allows a remote attacker... |
| CVE-2024-32936 | MEDIUM | 4.7 | 0.1% | Jun 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: media: ti: j721e-csi2rx: Fix races while restarting... |
| CVE-2024-5862 | HIGH | 7.5 | 0.5% | Jun 24, 2024 | Improper Restriction of Excessive Authentication Attempts vulnerability in Mia Technology Inc. Mia-Med Health Aplication... |
| CVE-2024-4839 | LOW | 3.3 | 0.2% | Jun 24, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the 'Servers Configurations' function of the parisneo/lollms... |
| CVE-2024-3264 | MEDIUM | 5.3 | 0.2% | Jun 24, 2024 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows S... |
| CVE-2024-37233 | MEDIUM | 4.3 | 0.4% | Jun 24, 2024 | Improper Authentication vulnerability in Play.Ht allows Accessing Functionality Not Properly Constrained by ACLs.This is... |
| CVE-2024-37231 | CRITICAL | 9.1 | 0.6% | Jun 24, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salon Booking System Sal... |
| CVE-2024-37228 | CRITICAL | 9.8 | 0.5% | Jun 24, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affe... |
| CVE-2024-37111 | HIGH | 7.5 | 0.5% | Jun 24, 2024 | Missing Authorization vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from ... |
| CVE-2024-37109 | HIGH | 8.8 | 0.5% | Jun 24, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows ... |
| CVE-2024-37107 | HIGH | 8.8 | 0.4% | Jun 24, 2024 | Improper Privilege Management vulnerability in Membership Software WishList Member X allows Privilege Escalation.This is... |
| CVE-2024-37092 | HIGH | 8.8 | 0.5% | Jun 24, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consultin... |
| CVE-2024-37091 | HIGH | 8.8 | 1.2% | Jun 24, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Cons... |
| CVE-2024-37089 | CRITICAL | 9.8 | 0.6% | Jun 24, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consultin... |
| CVE-2024-36038 | MEDIUM | 6.3 | 1.4% | Jun 24, 2024 | Zoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerabi... |
| CVE-2024-6160 | CRITICAL | 9.3 | 0.5% | Jun 24, 2024 | SQL Injection vulnerability in MegaBIP software allows attacker to disclose the contents of the database, obtain session... |
| CVE-2024-29868 | CRITICAL | 9.1 | 6.0% | Jun 24, 2024 | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-regist... |
| CVE-2024-5683 | CRITICAL | 9.8 | 0.5% | Jun 24, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Next4Biz CRM & BPM Software Business Process ... |
| CVE-2024-4754 | MEDIUM | 5.4 | 0.2% | Jun 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM... |
| CVE-2024-36497 | CRITICAL | 9.1 | 0.5% | Jun 24, 2024 | The decrypted configuration file contains the password in cleartext which is used to configure WINSelect. It can be use... |
| CVE-2024-36496 | HIGH | 7.5 | 0.7% | Jun 24, 2024 | The configuration file is encrypted with a static key derived from a static five-character password which allows an att... |
| CVE-2024-36495 | HIGH | 7.7 | 0.3% | Jun 24, 2024 | The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file syst... |
| CVE-2024-27136 | MEDIUM | 6.1 | 59.4% | Jun 24, 2024 | XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now