2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-7120CRITICAL9.8A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. Th...
CVE-2024-4447CRITICAL9.9In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via the Direct Web Remoting...
CVE-2024-41473CRITICAL9.8Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/Wr...
CVE-2024-41468CRITICAL9.8Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform...
CVE-2024-24621CRITICAL9.8Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality. Remote, ano...
CVE-2024-38289CRITICAL9.8A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x all...
CVE-2024-38287CRITICAL9.8The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticat...
CVE-2024-7007CRITICAL9.8Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an ...
CVE-2024-7081CRITICAL9.8A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been rated as critical. Affected by th...
CVE-2024-41461CRITICAL9.8Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ...
CVE-2024-41460CRITICAL9.8Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at...
CVE-2024-41459CRITICAL9.8Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword param...
CVE-2024-41551CRITICAL9.8CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_order_i...
CVE-2024-36535CRITICAL9.8Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining t...
CVE-2024-36533CRITICAL9.8Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining th...
CVE-2024-36536CRITICAL9.8Insecure permissions in fabedge v0.8.1 allows attackers to access sensitive data and escalate privileges by obtaining th...
CVE-2024-41662CRITICAL9.6VNote is a note-taking platform. A Cross-Site Scripting (XSS) vulnerability has been identified in the Markdown renderin...
CVE-2024-41110CRITICAL9.9Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detect...
CVE-2024-36540CRITICAL9.8Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by ob...
CVE-2024-36539CRITICAL9.8Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining t...
CVE-2024-40422CRITICAL9.1The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr...
CVE-2024-41914CRITICAL9A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re...
CVE-2024-6327CRITICAL9.8In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible ...
CVE-2024-6096CRITICAL9.8In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object inject...
CVE-2024-7066CRITICAL9.8A vulnerability was found in F-logic DataCube3 1.0. It has been declared as critical. Affected by this vulnerability is ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now