2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37654 | MEDIUM | 6.1 | 0.2% | Jun 21, 2024 | An issue in BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD,... |
| CVE-2024-36532 | CRITICAL | 10 | 0.5% | Jun 21, 2024 | Insecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the... |
| CVE-2024-34989 | CRITICAL | 9.8 | 0.5% | Jun 21, 2024 | In the module RSI PDF/HTML catalog evolution (prestapdf) <= 7.0.0 from RSI for PrestaShop, a guest can perform SQL injec... |
| CVE-2024-34452 | MEDIUM | 6.1 | 0.7% | Jun 21, 2024 | CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document. |
| CVE-2024-6241 | CRITICAL | 9.8 | 0.5% | Jun 21, 2024 | A vulnerability was found in Pear Admin Boot up to 2.0.2 and classified as critical. This issue affects the function get... |
| CVE-2024-37675 | MEDIUM | 5.4 | 0.6% | Jun 21, 2024 | Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute... |
| CVE-2024-37673 | MEDIUM | 5.4 | 0.6% | Jun 21, 2024 | Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute... |
| CVE-2024-37672 | MEDIUM | 5.4 | 0.6% | Jun 21, 2024 | Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute... |
| CVE-2024-37671 | MEDIUM | 5.4 | 0.6% | Jun 21, 2024 | Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute... |
| CVE-2024-35537 | HIGH | 7.5 | 0.3% | Jun 21, 2024 | TVS Motor Company Limited TVS Connect Android v4.6.0 and IOS v5.0.0 was discovered to insecurely handle the RSA key pair... |
| CVE-2024-37790 | — | — | — | Jun 21, 2024 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2024-35781 | MEDIUM | 6.5 | 0.5% | Jun 21, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YAHMAN Word Balloon allo... |
| CVE-2024-35778 | HIGH | 8.8 | 0.6% | Jun 21, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in John West Slideshow SE P... |
| CVE-2024-35767 | HIGH | 7.2 | 0.5% | Jun 21, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Bogdan Bendziukov Squeeze allows Code Injection.This is... |
| CVE-2024-6240 | CRITICAL | 10 | 0.3% | Jun 21, 2024 | Improper privilege management vulnerability in Parallels Desktop Software, which affects versions earlier than 19.3.0. A... |
| CVE-2024-6239 | HIGH | 7.5 | 0.8% | Jun 21, 2024 | A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. B... |
| CVE-2024-37230 | HIGH | 8.8 | 0.2% | Jun 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Book Landing Page.This issue affects Book Landing Page: fr... |
| CVE-2024-37227 | HIGH | 8.8 | 0.2% | Jun 21, 2024 | Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a throug... |
| CVE-2024-37212 | HIGH | 8.8 | 0.2% | Jun 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Ali2Woo Ali2Woo Lite.This issue affects Ali2Woo Lite: from n/a throug... |
| CVE-2024-37198 | HIGH | 8.8 | 0.2% | Jun 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in blazethemes Digital Newspaper.This issue affects Digital Newspaper: f... |
| CVE-2024-37118 | HIGH | 8.8 | 0.2% | Jun 21, 2024 | Cross Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Automator Pro.This issue affects Uncanny Automato... |
| CVE-2024-5059 | HIGH | 7.5 | 0.4% | Jun 21, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Event Management Tickets Booking.T... |
| CVE-2024-35776 | HIGH | 7.5 | 0.4% | Jun 21, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exeebit phpinfo() WP.This issue affects phpi... |
| CVE-2024-35772 | HIGH | 8.8 | 0.2% | Jun 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in presscustomizr Hueman.This issue affects Hueman: from n/a through 3.7... |
| CVE-2024-35771 | HIGH | 8.8 | 0.2% | Jun 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in presscustomizr Customizr.This issue affects Customizr: from n/a throu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now