2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34211HIGH8.8TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample...
CVE-2024-34210HIGH7.3TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the Clo...
CVE-2024-34209CRITICAL9.8TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFi...
CVE-2024-34207HIGH8.8TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setStaticDh...
CVE-2024-34206MEDIUM6.5TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the set...
CVE-2024-34205HIGH7.3TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the download_firmwa...
CVE-2024-34204CRITICAL9.8TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the set...
CVE-2024-34203LOW3.8TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setLanguage...
CVE-2024-34202MEDIUM6.5TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setMacFilte...
CVE-2024-34201HIGH7.3TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the getSaveConf...
CVE-2024-34200HIGH8.8TOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQo...
CVE-2024-34199HIGH8.6TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sendi...
CVE-2024-34196HIGH8.8Totolink AC1200 Wireless Dual Band Gigabit Router A3002RU_V3 Firmware V3.0.0-B20230809.1615 is vulnerable to Buffer Over...
CVE-2024-34081MEDIUM4.8MantisBT (Mantis Bug Tracker) is an open source issue tracker. Improper escaping of a custom field's name allows an att...
CVE-2024-34080MEDIUM5.3MantisBT (Mantis Bug Tracker) is an open source issue tracker. If an issue references a note that belongs to another iss...
CVE-2024-34079LOW3.7octo-sts is a GitHub App that acts like a Security Token Service (STS) for the Github API. This vulnerability can spike ...
CVE-2024-34077HIGH7.3MantisBT (Mantis Bug Tracker) is an open source issue tracker. Insufficient access control in the registration and passw...
CVE-2024-34074MEDIUM6.1Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument...
CVE-2024-34070CRITICAL9.6Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnera...
CVE-2024-33956MEDIUM4.3Missing Authorization vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom...
CVE-2024-33955MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Freesia Free...
CVE-2024-33954MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atanas Yonkov Plis...
CVE-2024-33953MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt van Andel Adv...
CVE-2024-33952MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Uni...
CVE-2024-33951MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adam DeHaven Perfe...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now