2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-29000MEDIUM4.3The SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the we...
CVE-2024-35580CRITICAL9.8Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.
CVE-2024-35579HIGH7.7Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv.
CVE-2024-35578HIGH8Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formSetIptv.
CVE-2024-35576MEDIUM5.2Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.
CVE-2024-35571CRITICAL9.8Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.
CVE-2024-34949HIGH8.2SQL injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function Orde...
CVE-2024-34193HIGH7.5smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vu...
CVE-2024-31714HIGH7.5Buffer Overflow vulnerability in Waxlab wax v.0.9-3 and before allows an attacker to cause a denial of service via the L...
CVE-2024-29651HIGH8.1A Prototype Pollution issue in API Dev Tools json-schema-ref-parser v.11.0.0 and v.11.1.0 allows a remote attacker to ex...
CVE-2024-24293HIGH8.8A Prototype Pollution issue in MiguelCastillo @bit/loader v.10.0.3 allows an attacker to execute arbitrary code via the ...
CVE-2024-34948HIGH7.5An issue in Quanxun Huiju Network Technology(Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 allows attackers to ...
CVE-2024-34947CRITICAL9.4Quanxun Huiju Network Technology (Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 was discovered to be vulnerable...
CVE-2024-24294CRITICAL9.8A Prototype Pollution issue in Blackprint @blackprint/engine v.0.9.0 allows an attacker to execute arbitrary code via th...
CVE-2024-0401HIGH7.2ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and r...
CVE-2024-4151HIGH8.1An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users can view and update any p...
CVE-2024-3482HIGH8.7A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager a...
CVE-2024-34953HIGH7.5An issue in taurusxin ncmdump v1.3.2 allows attackers to cause a Denial of Service (DoS) via memory exhaustion by supply...
CVE-2024-34952MEDIUM5taurusxin ncmdump v1.3.2 was discovered to contain a segmentation violation via the NeteaseCrypt::FixMetadata() function...
CVE-2024-2835HIGH8.7A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Enterprise Security Manager a...
CVE-2024-4287HIGH7.2In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. ...
CVE-2024-27312HIGH8.1Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged use...
CVE-2024-4323CRITICAL9.8A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s...
CVE-2024-5137MEDIUM4.8A vulnerability classified as problematic was found in PHPGurukul Directory Management System 1.0. Affected by this vuln...
CVE-2024-36009MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ax25: Fix netdev refcount issue The dev_tracker is...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now