2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35374 | CRITICAL | 9.8 | 2.7% | May 24, 2024 | Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing ... |
| CVE-2024-35373 | CRITICAL | 9.8 | 1.2% | May 24, 2024 | Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php. |
| CVE-2024-35232 | LOW | 3.7 | 0.5% | May 24, 2024 | github.com/huandu/facebook is a Go package that fully supports the Facebook Graph API with file upload, batch request an... |
| CVE-2024-35388 | HIGH | 8.8 | 2.5% | May 24, 2024 | TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the fun... |
| CVE-2024-33471 | HIGH | 7.2 | 0.3% | May 24, 2024 | An issue in the Sensor Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to SMTP credentials in pl... |
| CVE-2024-35387 | CRITICAL | 9.8 | 6.1% | May 24, 2024 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the func... |
| CVE-2024-36049 | MEDIUM | 6.5 | 0.5% | May 24, 2024 | Aptos Wisal payroll accounting before 7.1.6 uses hardcoded credentials in the Windows client to fetch the complete list ... |
| CVE-2024-35396 | CRITICAL | 9.8 | 0.6% | May 24, 2024 | TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/pr... |
| CVE-2024-35395 | HIGH | 8.8 | 0.5% | May 24, 2024 | TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sampl... |
| CVE-2024-34995 | MEDIUM | 4.3 | 0.3% | May 24, 2024 | svnWebUI v1.8.3 was discovered to contain an arbitrary file deletion vulnerability via the dirTemps parameter under com.... |
| CVE-2024-33427 | — | — | — | May 24, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-35618 | HIGH | 7.5 | 0.4% | May 24, 2024 | PingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer. |
| CVE-2024-35340 | HIGH | 8.6 | 1.2% | May 24, 2024 | Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at ip... |
| CVE-2024-35339 | CRITICAL | 9.8 | 1.8% | May 24, 2024 | Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/gofo... |
| CVE-2024-33809 | MEDIUM | 6.5 | 0.4% | May 24, 2024 | PingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and ... |
| CVE-2024-33470 | MEDIUM | 4.9 | 0.2% | May 24, 2024 | An issue in the SMTP Email Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to credentials in pla... |
| CVE-2024-31510 | CRITICAL | 9.8 | 0.6% | May 24, 2024 | An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signatur... |
| CVE-2024-22588 | MEDIUM | 6.5 | 0.3% | May 24, 2024 | Kwik commit 745fd4e2 does not discard unused encryption keys. |
| CVE-2024-5273 | MEDIUM | 4.3 | 0.8% | May 24, 2024 | Jenkins Report Info Plugin 1.2 and earlier does not perform path validation of the workspace directory while serving rep... |
| CVE-2024-35595 | MEDIUM | 6.1 | 0.4% | May 24, 2024 | An arbitrary file upload vulnerability in the File Preview function of Xintongda OA v2023.12.30.1 allows attackers to ex... |
| CVE-2024-35593 | MEDIUM | 5.5 | 0.2% | May 24, 2024 | An arbitrary file upload vulnerability in the File preview function of Raingad IM v4.1.4 allows attackers to execute arb... |
| CVE-2024-35592 | CRITICAL | 9.6 | 0.6% | May 24, 2024 | An arbitrary file upload vulnerability in the Upload function of Box-IM v2.0 allows attackers to execute arbitrary code ... |
| CVE-2024-35591 | MEDIUM | 5.4 | 0.4% | May 24, 2024 | An arbitrary file upload vulnerability in O2OA v8.3.8 allows attackers to execute arbitrary code via uploading a crafted... |
| CVE-2024-5318 | MEDIUM | 5.3 | 0.4% | May 24, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.11 prior to 16.10.6, starting from ... |
| CVE-2024-5312 | MEDIUM | 6.3 | 0.3% | May 24, 2024 | PHP Server Monitor, version 3.2.0, is vulnerable to an XSS via the /phpservermon-3.2.0/vendor/phpmailer/phpmailer/test_s... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now