2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29404 | HIGH | 7.8 | 0.5% | Dec 3, 2024 | An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary co... |
| CVE-2024-54000 | HIGH | 7.5 | 0.4% | Dec 3, 2024 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor... |
| CVE-2024-11391 | HIGH | 7.5 | 0.7% | Dec 3, 2024 | The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati... |
| CVE-2024-42422 | HIGH | 7.5 | 0.3% | Dec 3, 2024 | Dell NetWorker, version(s) 19.10, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unaut... |
| CVE-2024-10074 | HIGH | 7.8 | 0.2% | Dec 3, 2024 | in OpenHarmony v4.1.1 and prior versions allow a local attacker cause the common permission is upgraded to root through ... |
| CVE-2024-47476 | HIGH | 7.8 | 0.1% | Dec 3, 2024 | Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vuln... |
| CVE-2024-45106 | HIGH | 8.1 | 0.5% | Dec 3, 2024 | Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos us... |
| CVE-2024-49420 | HIGH | 7.5 | 0.5% | Dec 3, 2024 | Improper handling of responses in GamingHub prior to version 6.1.04.6 in Korea, 7.1.03.7 in Global allows remote attacke... |
| CVE-2024-49413 | HIGH | 7.8 | 0.2% | Dec 3, 2024 | Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers t... |
| CVE-2024-49410 | HIGH | 7.8 | 0.2% | Dec 3, 2024 | Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary c... |
| CVE-2024-45068 | HIGH | 7.1 | 0.3% | Dec 3, 2024 | Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. ... |
| CVE-2024-9200 | HIGH | 7.2 | 1.1% | Dec 3, 2024 | A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG400... |
| CVE-2024-8748 | HIGH | 7.5 | 0.5% | Dec 3, 2024 | A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmwa... |
| CVE-2024-53937 | HIGH | 8.8 | 0.4% | Dec 2, 2024 | An issue was discovered on Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNE... |
| CVE-2024-53941 | HIGH | 8.8 | 0.5% | Dec 2, 2024 | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. A remote ... |
| CVE-2024-53940 | HIGH | 8.8 | 2.2% | Dec 2, 2024 | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. Certain /... |
| CVE-2024-53939 | HIGH | 8.8 | 2.8% | Dec 2, 2024 | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-... |
| CVE-2024-53938 | HIGH | 8.8 | 0.5% | Dec 2, 2024 | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNE... |
| CVE-2024-53375 | HIGH | 8 | 40.7% | Dec 2, 2024 | An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exi... |
| CVE-2024-39890 | HIGH | 8.1 | 0.4% | Dec 2, 2024 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 108... |
| CVE-2024-39343 | HIGH | 7 | 0.4% | Dec 2, 2024 | An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, 24... |
| CVE-2024-53484 | HIGH | 8.8 | 0.5% | Dec 2, 2024 | Ever Traduora 0.20.0 and below is vulnerable to Privilege Escalation due to the use of a hard-coded JWT signing key. |
| CVE-2024-53564 | HIGH | 7.2 | 0.3% | Dec 2, 2024 | A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) fil... |
| CVE-2024-53992 | HIGH | 8.8 | 0.4% | Dec 2, 2024 | unzip-bot is a Telegram bot to extract various types of archives. Users could exploit unsanitized inputs to inject malic... |
| CVE-2024-52806 | HIGH | 8.3 | 0.4% | Dec 2, 2024 | SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untrusted) XML document, ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now