2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5298 | HIGH | 8.8 | 1.8% | May 23, 2024 | D-Link D-View queryDeviceCustomMonitorResult Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerab... |
| CVE-2024-5297 | HIGH | 8.8 | 1.9% | May 23, 2024 | D-Link D-View executeWmicCmd Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote att... |
| CVE-2024-5296 | CRITICAL | 9.8 | 1.1% | May 23, 2024 | D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote ... |
| CVE-2024-5295 | HIGH | 8.8 | 2.0% | May 23, 2024 | D-Link G416 flupl self Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent... |
| CVE-2024-5294 | MEDIUM | 6.5 | 0.5% | May 23, 2024 | D-Link DIR-3040 prog.cgi websSecurityHandler Memory Leak Denial-of-Service Vulnerability. This vulnerability allows netw... |
| CVE-2024-5293 | HIGH | 8.8 | 1.6% | May 23, 2024 | D-Link DIR-2640 HTTP Referer Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ... |
| CVE-2024-5292 | HIGH | 7.8 | 0.5% | May 23, 2024 | D-Link Network Assistant Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability a... |
| CVE-2024-5291 | HIGH | 8.8 | 2.0% | May 23, 2024 | D-Link DIR-2150 GetDeviceSettings Target Command Injection Remote Code Execution Vulnerability. This vulnerability allow... |
| CVE-2024-5247 | HIGH | 8.8 | 26.9% | May 23, 2024 | NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. Th... |
| CVE-2024-5246 | HIGH | 8.8 | 31.3% | May 23, 2024 | NETGEAR ProSAFE Network Management System Tomcat Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2024-5245 | HIGH | 7.8 | 0.6% | May 23, 2024 | NETGEAR ProSAFE Network Management System Default Credentials Local Privilege Escalation Vulnerability. This vulnerabili... |
| CVE-2024-5244 | MEDIUM | 4.2 | 0.3% | May 23, 2024 | TP-Link Omada ER605 Reliance on Security Through Obscurity Vulnerability. This vulnerability allows network-adjacent att... |
| CVE-2024-5243 | HIGH | 7.5 | 0.8% | May 23, 2024 | TP-Link Omada ER605 Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent atta... |
| CVE-2024-5242 | HIGH | 7.5 | 0.8% | May 23, 2024 | TP-Link Omada ER605 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-a... |
| CVE-2024-5228 | HIGH | 7.5 | 0.5% | May 23, 2024 | TP-Link Omada ER605 Comexe DDNS Response Handling Heap-based Buffer Overflow Remote Code Execution Vulnerability. This ... |
| CVE-2024-5227 | HIGH | 7.5 | 0.7% | May 23, 2024 | TP-Link Omada ER605 PPTP VPN username Command Injection Remote Code Execution Vulnerability. This vulnerability allows n... |
| CVE-2024-5202 | HIGH | 7.7 | 0.4% | May 23, 2024 | Arbitrary File Read in OpenText Dimensions RM allows authenticated users to read files stored on the server via webservi... |
| CVE-2024-5201 | HIGH | 8.8 | 0.4% | May 23, 2024 | Privilege Escalation in OpenText Dimensions RM allows an authenticated user to escalate there privilege to the privilege... |
| CVE-2024-35570 | CRITICAL | 9.8 | 0.9% | May 23, 2024 | An arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows ... |
| CVE-2024-35375 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.... |
| CVE-2024-35080 | CRITICAL | 9.8 | 0.6% | May 23, 2024 | An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code v... |
| CVE-2024-35079 | CRITICAL | 9.8 | 0.6% | May 23, 2024 | An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary... |
| CVE-2024-31843 | MEDIUM | 4.1 | 0.5% | May 23, 2024 | An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as inp... |
| CVE-2024-5143 | MEDIUM | 6.8 | 0.4% | May 23, 2024 | A user with device administrative privileges can change existing SMTP server settings on the device, without having to r... |
| CVE-2024-4365 | MEDIUM | 6.4 | 0.3% | May 23, 2024 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_iframe_url_as_param_d... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now