2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8748 | HIGH | 7.5 | 0.5% | Dec 3, 2024 | A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmwa... |
| CVE-2024-53937 | HIGH | 8.8 | 0.4% | Dec 2, 2024 | An issue was discovered on Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNE... |
| CVE-2024-53941 | HIGH | 8.8 | 0.5% | Dec 2, 2024 | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. A remote ... |
| CVE-2024-53940 | HIGH | 8.8 | 2.2% | Dec 2, 2024 | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. Certain /... |
| CVE-2024-53939 | HIGH | 8.8 | 2.8% | Dec 2, 2024 | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-... |
| CVE-2024-53938 | HIGH | 8.8 | 0.5% | Dec 2, 2024 | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNE... |
| CVE-2024-53375 | HIGH | 8 | 40.7% | Dec 2, 2024 | An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exi... |
| CVE-2024-39890 | HIGH | 8.1 | 0.4% | Dec 2, 2024 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 108... |
| CVE-2024-39343 | HIGH | 7 | 0.4% | Dec 2, 2024 | An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, 24... |
| CVE-2024-53484 | HIGH | 8.8 | 0.5% | Dec 2, 2024 | Ever Traduora 0.20.0 and below is vulnerable to Privilege Escalation due to the use of a hard-coded JWT signing key. |
| CVE-2024-53564 | HIGH | 7.2 | 0.3% | Dec 2, 2024 | A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) fil... |
| CVE-2024-53992 | HIGH | 8.8 | 0.4% | Dec 2, 2024 | unzip-bot is a Telegram bot to extract various types of archives. Users could exploit unsanitized inputs to inject malic... |
| CVE-2024-52806 | HIGH | 8.3 | 0.4% | Dec 2, 2024 | SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untrusted) XML document, ... |
| CVE-2024-52596 | HIGH | 8.8 | 1.0% | Dec 2, 2024 | SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for ... |
| CVE-2024-50381 | HIGH | 8.8 | 0.5% | Dec 2, 2024 | A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim ... |
| CVE-2024-50380 | HIGH | 8.7 | 0.5% | Dec 2, 2024 | Snap One OVRC cloud uses the MAC address as an identifier to provide information when requested. An attacker can imperso... |
| CVE-2024-49763 | HIGH | 8.7 | 0.5% | Dec 2, 2024 | PlexRipper is a cross-platform media downloader for Plex. PlexRipper’s open CORS policy allows attackers to gain sensiti... |
| CVE-2024-53981 | HIGH | 7.5 | 0.6% | Dec 2, 2024 | python-multipart is a streaming multipart parser for Python. When parsing form data, python-multipart skips line breaks ... |
| CVE-2024-53862 | HIGH | 7.5 | 0.6% | Dec 2, 2024 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. When us... |
| CVE-2024-46908 | HIGH | 8.8 | 2.2% | Dec 2, 2024 | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged ... |
| CVE-2024-46907 | HIGH | 8.8 | 2.2% | Dec 2, 2024 | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged ... |
| CVE-2024-46906 | HIGH | 8.8 | 40.6% | Dec 2, 2024 | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged ... |
| CVE-2024-46905 | HIGH | 8.8 | 2.2% | Dec 2, 2024 | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated lower-privilege... |
| CVE-2024-31669 | HIGH | 7.5 | 0.4% | Dec 2, 2024 | rizin before Release v0.6.3 is vulnerable to Uncontrolled Resource Consumption via bin_pe_parse_imports, Pe_r_bin_pe_par... |
| CVE-2024-29645 | HIGH | 7.8 | 0.2% | Dec 2, 2024 | Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the parse_die... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now