2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34211 | HIGH | 8.8 | 0.5% | May 14, 2024 | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample... |
| CVE-2024-34210 | HIGH | 7.3 | 1.2% | May 14, 2024 | TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the Clo... |
| CVE-2024-34209 | CRITICAL | 9.8 | 0.9% | May 14, 2024 | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpPortFi... |
| CVE-2024-34207 | HIGH | 8.8 | 0.8% | May 14, 2024 | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setStaticDh... |
| CVE-2024-34206 | MEDIUM | 6.5 | 1.3% | May 14, 2024 | TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the set... |
| CVE-2024-34205 | HIGH | 7.3 | 1.2% | May 14, 2024 | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the download_firmwa... |
| CVE-2024-34204 | CRITICAL | 9.8 | 1.9% | May 14, 2024 | TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the set... |
| CVE-2024-34203 | LOW | 3.8 | 0.6% | May 14, 2024 | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setLanguage... |
| CVE-2024-34202 | MEDIUM | 6.5 | 0.7% | May 14, 2024 | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setMacFilte... |
| CVE-2024-34201 | HIGH | 7.3 | 0.6% | May 14, 2024 | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the getSaveConf... |
| CVE-2024-34200 | HIGH | 8.8 | 0.9% | May 14, 2024 | TOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQo... |
| CVE-2024-34199 | HIGH | 8.6 | 1.2% | May 14, 2024 | TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sendi... |
| CVE-2024-34196 | HIGH | 8.8 | 0.7% | May 14, 2024 | Totolink AC1200 Wireless Dual Band Gigabit Router A3002RU_V3 Firmware V3.0.0-B20230809.1615 is vulnerable to Buffer Over... |
| CVE-2024-34081 | MEDIUM | 4.8 | 0.6% | May 14, 2024 | MantisBT (Mantis Bug Tracker) is an open source issue tracker. Improper escaping of a custom field's name allows an att... |
| CVE-2024-34080 | MEDIUM | 5.3 | 0.7% | May 14, 2024 | MantisBT (Mantis Bug Tracker) is an open source issue tracker. If an issue references a note that belongs to another iss... |
| CVE-2024-34079 | LOW | 3.7 | 0.6% | May 14, 2024 | octo-sts is a GitHub App that acts like a Security Token Service (STS) for the Github API. This vulnerability can spike ... |
| CVE-2024-34077 | HIGH | 7.3 | 1.2% | May 14, 2024 | MantisBT (Mantis Bug Tracker) is an open source issue tracker. Insufficient access control in the registration and passw... |
| CVE-2024-34074 | MEDIUM | 6.1 | 0.6% | May 14, 2024 | Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument... |
| CVE-2024-34070 | CRITICAL | 9.6 | 1.0% | May 14, 2024 | Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnera... |
| CVE-2024-33956 | MEDIUM | 4.3 | 0.4% | May 14, 2024 | Missing Authorization vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom... |
| CVE-2024-33955 | MEDIUM | 6.5 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Freesia Free... |
| CVE-2024-33954 | MEDIUM | 6.5 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atanas Yonkov Plis... |
| CVE-2024-33953 | MEDIUM | 6.5 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt van Andel Adv... |
| CVE-2024-33952 | MEDIUM | 6.5 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Uni... |
| CVE-2024-33951 | MEDIUM | 6.5 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adam DeHaven Perfe... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now