2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41336HIGH7.5Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vi...
CVE-2024-41335HIGH7.5Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vi...
CVE-2024-41334HIGH8.8Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vi...
CVE-2024-58042MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: rhashtable: Fix potential deadlock by moving schedu...
CVE-2024-58034HIGH7.8In the Linux kernel, the following vulnerability has been resolved: memory: tegra20-emc: fix an OF node reference bug i...
CVE-2024-58022MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mailbox: th1520: Fix a NULL vs IS_ERR() bug The de...
CVE-2024-54957MEDIUM6.1Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permi...
CVE-2024-53944CRITICAL9.8An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B ...
CVE-2024-53408MEDIUM5.4AVE System Web Client v2.1.131.13992 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2024-9285MEDIUM5.3A vulnerability was found in Tu Yafeng Via Browser up to 5.9.0 on Android. It has been rated as problematic. This issue ...
CVE-2024-56812MEDIUM5.5IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret...
CVE-2024-56811LOW3.3IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret...
CVE-2024-56810LOW3.3IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret...
CVE-2024-56496LOW3.3IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret...
CVE-2024-56495LOW3.3IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret...
CVE-2024-56494LOW3.3IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret...
CVE-2024-56493LOW3.3IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret...
CVE-2024-54170MEDIUM5.5IBM EntireX 11.1 could allow a local user to cause a denial of service due to use of a regular expression with an ineffi...
CVE-2024-54169MEDIUM6.5IBM EntireX 11.1 could allow an authenticated attacker to traverse directories on the system. An attacker could send a s...
CVE-2024-13148CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yukseloglu Filter ...
CVE-2024-9334HIGH8.2Use of Hard-coded Credentials, Storage of Sensitive Data in a Mechanism without Access Control vulnerability in E-Kent P...
CVE-2024-13402MEDIUM5.4The Buddyboss Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_title’ parameter ...
CVE-2024-13217MEDIUM4.3The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in...
CVE-2024-10918CRITICAL9.8Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus re...
CVE-2024-13734MEDIUM5.4The Card Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Profi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now