2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7120 | CRITICAL | 9.8 | 93.4% | Jul 26, 2024 | A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. Th... |
| CVE-2024-4447 | CRITICAL | 9.9 | 0.5% | Jul 26, 2024 | In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via the Direct Web Remoting... |
| CVE-2024-41473 | CRITICAL | 9.8 | 6.7% | Jul 25, 2024 | Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/Wr... |
| CVE-2024-41468 | CRITICAL | 9.8 | 4.6% | Jul 25, 2024 | Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform... |
| CVE-2024-24621 | CRITICAL | 9.8 | 1.2% | Jul 25, 2024 | Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality. Remote, ano... |
| CVE-2024-38289 | CRITICAL | 9.8 | 40.9% | Jul 25, 2024 | A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x all... |
| CVE-2024-38287 | CRITICAL | 9.8 | 0.5% | Jul 25, 2024 | The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticat... |
| CVE-2024-7007 | CRITICAL | 9.8 | 0.6% | Jul 25, 2024 | Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an ... |
| CVE-2024-7081 | CRITICAL | 9.8 | 0.6% | Jul 24, 2024 | A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been rated as critical. Affected by th... |
| CVE-2024-41461 | CRITICAL | 9.8 | 0.6% | Jul 24, 2024 | Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ... |
| CVE-2024-41460 | CRITICAL | 9.8 | 0.6% | Jul 24, 2024 | Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at... |
| CVE-2024-41459 | CRITICAL | 9.8 | 0.6% | Jul 24, 2024 | Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword param... |
| CVE-2024-41551 | CRITICAL | 9.8 | 0.4% | Jul 24, 2024 | CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_order_i... |
| CVE-2024-36535 | CRITICAL | 9.8 | 0.5% | Jul 24, 2024 | Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining t... |
| CVE-2024-36533 | CRITICAL | 9.8 | 0.5% | Jul 24, 2024 | Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining th... |
| CVE-2024-36536 | CRITICAL | 9.8 | 0.5% | Jul 24, 2024 | Insecure permissions in fabedge v0.8.1 allows attackers to access sensitive data and escalate privileges by obtaining th... |
| CVE-2024-41662 | CRITICAL | 9.6 | 1.6% | Jul 24, 2024 | VNote is a note-taking platform. A Cross-Site Scripting (XSS) vulnerability has been identified in the Markdown renderin... |
| CVE-2024-41110 | CRITICAL | 9.9 | 16.5% | Jul 24, 2024 | Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detect... |
| CVE-2024-36540 | CRITICAL | 9.8 | 0.4% | Jul 24, 2024 | Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by ob... |
| CVE-2024-36539 | CRITICAL | 9.8 | 1.3% | Jul 24, 2024 | Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining t... |
| CVE-2024-40422 | CRITICAL | 9.1 | 11.4% | Jul 24, 2024 | The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path tr... |
| CVE-2024-41914 | CRITICAL | 9 | 0.5% | Jul 24, 2024 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated re... |
| CVE-2024-6327 | CRITICAL | 9.8 | 2.0% | Jul 24, 2024 | In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible ... |
| CVE-2024-6096 | CRITICAL | 9.8 | 0.9% | Jul 24, 2024 | In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object inject... |
| CVE-2024-7066 | CRITICAL | 9.8 | 3.4% | Jul 24, 2024 | A vulnerability was found in F-logic DataCube3 1.0. It has been declared as critical. Affected by this vulnerability is ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now