2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-37566CRITICAL9.8Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.
CVE-2024-36047CRITICAL9.8Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.
CVE-2024-36046CRITICAL9.8Infoblox NIOS through 8.6.4 executes with more privileges than required.
CVE-2024-38292CRITICAL9.8In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which ma...
CVE-2024-38291HIGH8.8In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege esc...
CVE-2024-38290MEDIUM5.3In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.
CVE-2024-55160CRITICAL9.8GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/op...
CVE-2024-51139CRITICAL9.8Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862...
CVE-2024-51138CRITICAL9.8Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3...
CVE-2024-41340HIGH8.4An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior t...
CVE-2024-41339HIGH8.8An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620...
CVE-2024-41338HIGH7.5A NULL pointer dereference in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor...
CVE-2024-41336HIGH7.5Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vi...
CVE-2024-41335HIGH7.5Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vi...
CVE-2024-41334HIGH8.8Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vi...
CVE-2024-58042MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: rhashtable: Fix potential deadlock by moving schedu...
CVE-2024-58034HIGH7.8In the Linux kernel, the following vulnerability has been resolved: memory: tegra20-emc: fix an OF node reference bug i...
CVE-2024-58022MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mailbox: th1520: Fix a NULL vs IS_ERR() bug The de...
CVE-2024-54957MEDIUM6.1Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permi...
CVE-2024-53944CRITICAL9.8An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B ...
CVE-2024-53408MEDIUM5.4AVE System Web Client v2.1.131.13992 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2024-9285MEDIUM5.3A vulnerability was found in Tu Yafeng Via Browser up to 5.9.0 on Android. It has been rated as problematic. This issue ...
CVE-2024-56812MEDIUM5.5IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret...
CVE-2024-56811LOW3.3IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret...
CVE-2024-56810LOW3.3IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now