2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-35374CRITICAL9.8Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing ...
CVE-2024-35373CRITICAL9.8Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.
CVE-2024-35232LOW3.7github.com/huandu/facebook is a Go package that fully supports the Facebook Graph API with file upload, batch request an...
CVE-2024-35388HIGH8.8TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the fun...
CVE-2024-33471HIGH7.2An issue in the Sensor Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to SMTP credentials in pl...
CVE-2024-35387CRITICAL9.8TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the http_host parameter in the func...
CVE-2024-36049MEDIUM6.5Aptos Wisal payroll accounting before 7.1.6 uses hardcoded credentials in the Windows client to fetch the complete list ...
CVE-2024-35396CRITICAL9.8TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password for telnet in /web_cste/cgi-bin/pr...
CVE-2024-35395HIGH8.8TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sampl...
CVE-2024-34995MEDIUM4.3svnWebUI v1.8.3 was discovered to contain an arbitrary file deletion vulnerability via the dirTemps parameter under com....
CVE-2024-33427Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-35618HIGH7.5PingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer.
CVE-2024-35340HIGH8.6Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at ip...
CVE-2024-35339CRITICAL9.8Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/gofo...
CVE-2024-33809MEDIUM6.5PingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and ...
CVE-2024-33470MEDIUM4.9An issue in the SMTP Email Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to credentials in pla...
CVE-2024-31510CRITICAL9.8An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signatur...
CVE-2024-22588MEDIUM6.5Kwik commit 745fd4e2 does not discard unused encryption keys.
CVE-2024-5273MEDIUM4.3Jenkins Report Info Plugin 1.2 and earlier does not perform path validation of the workspace directory while serving rep...
CVE-2024-35595MEDIUM6.1An arbitrary file upload vulnerability in the File Preview function of Xintongda OA v2023.12.30.1 allows attackers to ex...
CVE-2024-35593MEDIUM5.5An arbitrary file upload vulnerability in the File preview function of Raingad IM v4.1.4 allows attackers to execute arb...
CVE-2024-35592CRITICAL9.6An arbitrary file upload vulnerability in the Upload function of Box-IM v2.0 allows attackers to execute arbitrary code ...
CVE-2024-35591MEDIUM5.4An arbitrary file upload vulnerability in O2OA v8.3.8 allows attackers to execute arbitrary code via uploading a crafted...
CVE-2024-5318MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.11 prior to 16.10.6, starting from ...
CVE-2024-5312MEDIUM6.3PHP Server Monitor, version 3.2.0, is vulnerable to an XSS via the /phpservermon-3.2.0/vendor/phpmailer/phpmailer/test_s...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now