2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34470HIGH8.6An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability ...
CVE-2024-34466Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-34467. Reason: This candidate is a reservation d...
CVE-2024-34252HIGH7.5wasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentation fault via the function "Pres...
CVE-2024-34249CRITICAL9.8wasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation fault via the function "Deallo...
CVE-2024-34078MEDIUM6.1html-sanitizer is an allowlist-based HTML cleaner. If using `keep_typographic_whitespace=False` (which is the default), ...
CVE-2024-34069HIGH7.5Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an att...
CVE-2024-34064MEDIUM5.4Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non...
CVE-2024-33294CRITICAL9.1An issue in Library System using PHP/MySQli with Source Code V1.0 allows a remote attacker to execute arbitrary code via...
CVE-2024-33113MEDIUM5.3D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.
CVE-2024-33112HIGH7.5D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.
CVE-2024-33111MEDIUM5.4D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.
CVE-2024-33110CRITICAL9.1D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.
CVE-2024-32982HIGH8.2Litestar and Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.8.3, 2.7.2, and 2.6.4, a ...
CVE-2024-32972HIGH7.5go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to 1.13.15, a vulnerable n...
CVE-2024-23354HIGH7.8Memory corruption when the IOCTL call is interrupted by a signal.
CVE-2024-23351HIGH7.8Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.
CVE-2024-21480CRITICAL9.8Memory corruption while playing audio file having large-sized input buffer.
CVE-2024-21477HIGH7.5Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.
CVE-2024-21476HIGH7.8Memory corruption when the channel ID passed by user is not validated and further used.
CVE-2024-21475HIGH7.8Memory corruption when the payload received from firmware is not as per the expected protocol size.
CVE-2024-21474HIGH7.8Memory corruption when size of buffer from previous call is used without validation or re-initialization.
CVE-2024-21471HIGH7.8Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.
CVE-2024-4549HIGH7.5A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS...
CVE-2024-4548CRITICAL9.8An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'Recalcula...
CVE-2024-4547CRITICAL9.8A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'Recalculat...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now