2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-27174CRITICAL9.8Remote Command program allows an attacker to get Remote Code Execution. This vulnerability can be executed in combinatio...
CVE-2024-27173CRITICAL9.8Remote Command program allows an attacker to get Remote Code Execution by overwriting existing Python files containing e...
CVE-2024-27172CRITICAL9.8Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, se...
CVE-2024-27171HIGH7.4A remote attacker using the insecure upload functionality will be able to overwrite any Python file and get Remote Code ...
CVE-2024-27170HIGH7.4It was observed that all the Toshiba printers contain credentials used for WebDAV access in the readable file. Then, it ...
CVE-2024-27169HIGH8.4Toshiba printers provides API without authentication for internal access. A local attacker can bypass authentication in ...
CVE-2024-27168HIGH7.1It appears that some hardcoded keys are used for authentication to internal API. Knowing these private keys may allow at...
CVE-2024-27167HIGH7.4Toshiba printers use Sendmail to send emails to recipients. Sendmail is used with several insecure directories. A local ...
CVE-2024-27166HIGH7.4Coredump binaries in Toshiba printers have incorrect permissions. A local attacker can steal confidential information. A...
CVE-2024-27165HIGH7.8Toshiba printers contain a suidperl binary and it has a Local Privilege Escalation vulnerability. A local attacker can g...
CVE-2024-27164HIGH7.1Toshiba printers contain hardcoded credentials. As for the affected products/models/versions, see the reference URL.
CVE-2024-27163MEDIUM6.5Toshiba printers will display the password of the admin user in clear-text and additional passwords when sending 2 speci...
CVE-2024-27162MEDIUM6.1Toshiba printers provide a web interface that will load the JavaScript file. The file contains insecure codes vulnerable...
CVE-2024-27161MEDIUM6.2all the Toshiba printers have programs containing a hardcoded key used to encrypt files. An attacker can decrypt the enc...
CVE-2024-27160MEDIUM6.2All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt th...
CVE-2024-27159MEDIUM6.2All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt th...
CVE-2024-27158HIGH7.4All the Toshiba printers share the same hardcoded root password. As for the affected products/models/versions, see the r...
CVE-2024-27157MEDIUM6.8The sessions are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retr...
CVE-2024-27156MEDIUM6.8The session cookies, used for authentication, are stored in clear-text logs. An attacker can retrieve authentication ses...
CVE-2024-27155HIGH7.7The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise a...
CVE-2024-0892MEDIUM4.3The Schema App Structured Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2024-3080CRITICAL9.8Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in...
CVE-2024-3079HIGH7.2Certain models of ASUS routers have buffer overflow vulnerabilities, allowing remote attackers with administrative privi...
CVE-2024-27154MEDIUM6.2Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/version...
CVE-2024-27153HIGH7.4The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now