2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29000 | MEDIUM | 4.3 | 0.5% | May 20, 2024 | The SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the we... |
| CVE-2024-35580 | CRITICAL | 9.8 | 0.6% | May 20, 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv. |
| CVE-2024-35579 | HIGH | 7.7 | 0.4% | May 20, 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv. |
| CVE-2024-35578 | HIGH | 8 | 0.4% | May 20, 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv. |
| CVE-2024-35576 | MEDIUM | 5.2 | 0.3% | May 20, 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv. |
| CVE-2024-35571 | CRITICAL | 9.8 | 0.6% | May 20, 2024 | Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv. |
| CVE-2024-34949 | HIGH | 8.2 | 0.4% | May 20, 2024 | SQL injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function Orde... |
| CVE-2024-34193 | HIGH | 7.5 | 0.6% | May 20, 2024 | smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vu... |
| CVE-2024-31714 | HIGH | 7.5 | 0.4% | May 20, 2024 | Buffer Overflow vulnerability in Waxlab wax v.0.9-3 and before allows an attacker to cause a denial of service via the L... |
| CVE-2024-29651 | HIGH | 8.1 | 0.8% | May 20, 2024 | A Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to ex... |
| CVE-2024-24293 | HIGH | 8.8 | 0.7% | May 20, 2024 | A Prototype Pollution issue in MiguelCastillo @bit/loader v.10.0.3 allows an attacker to execute arbitrary code via the ... |
| CVE-2024-34948 | HIGH | 7.5 | 0.4% | May 20, 2024 | An issue in Quanxun Huiju Network Technology(Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 allows attackers to ... |
| CVE-2024-34947 | CRITICAL | 9.4 | 0.4% | May 20, 2024 | Quanxun Huiju Network Technology (Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 was discovered to be vulnerable... |
| CVE-2024-24294 | CRITICAL | 9.8 | 0.8% | May 20, 2024 | A Prototype Pollution issue in Blackprint @blackprint/engine v.0.9.0 allows an attacker to execute arbitrary code via th... |
| CVE-2024-0401 | HIGH | 7.2 | 0.7% | May 20, 2024 | ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and r... |
| CVE-2024-4151 | HIGH | 8.1 | 0.4% | May 20, 2024 | An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users can view and update any p... |
| CVE-2024-3482 | HIGH | 8.7 | 0.4% | May 20, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager a... |
| CVE-2024-34953 | HIGH | 7.5 | 0.6% | May 20, 2024 | An issue in taurusxin ncmdump v1.3.2 allows attackers to cause a Denial of Service (DoS) via memory exhaustion by supply... |
| CVE-2024-34952 | MEDIUM | 5 | 0.2% | May 20, 2024 | taurusxin ncmdump v1.3.2 was discovered to contain a segmentation violation via the NeteaseCrypt::FixMetadata() function... |
| CVE-2024-2835 | HIGH | 8.7 | 0.4% | May 20, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager a... |
| CVE-2024-4287 | HIGH | 7.2 | 0.6% | May 20, 2024 | In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. ... |
| CVE-2024-27312 | HIGH | 8.1 | 0.9% | May 20, 2024 | Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged use... |
| CVE-2024-4323 | CRITICAL | 9.8 | 28.3% | May 20, 2024 | A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s... |
| CVE-2024-5137 | MEDIUM | 4.8 | 0.5% | May 20, 2024 | A vulnerability classified as problematic was found in PHPGurukul Directory Management System 1.0. Affected by this vuln... |
| CVE-2024-36009 | MEDIUM | 5.5 | 0.2% | May 20, 2024 | In the Linux kernel, the following vulnerability has been resolved: ax25: Fix netdev refcount issue The dev_tracker is... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now