2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34048 | CRITICAL | 9.8 | 0.6% | Apr 30, 2024 | O-RAN RIC I-Release e2mgr lacks array size checks in E2nodeConfigUpdateNotificationHandler. |
| CVE-2024-34047 | MEDIUM | 4.3 | 0.3% | Apr 30, 2024 | O-RAN RIC I-Release e2mgr lacks array size checks in RicServiceUpdateHandler. |
| CVE-2024-34046 | HIGH | 7.5 | 0.5% | Apr 30, 2024 | The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->sctpParam... |
| CVE-2024-34045 | HIGH | 7.5 | 0.5% | Apr 30, 2024 | The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->counters[... |
| CVE-2024-34044 | MEDIUM | 5.3 | 0.5% | Apr 30, 2024 | The O-RAN E2T I-Release buildPrometheusList function can have a NULL pointer dereference because peerInfo can be NULL. |
| CVE-2024-34043 | MEDIUM | 5.3 | 0.2% | Apr 30, 2024 | O-RAN RICAPP kpimon-go I-Release has a segmentation violation via a certain E2AP-PDU message. |
| CVE-2024-33522 | MEDIUM | 6.7 | 0.2% | Apr 29, 2024 | In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Cal... |
| CVE-2024-33401 | MEDIUM | 4.4 | 0.2% | Apr 29, 2024 | Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to run arbitrary code via the mnum para... |
| CVE-2024-33350 | CRITICAL | 9.8 | 1.8% | Apr 29, 2024 | Directory Traversal vulnerability in TaoCMS v.3.0.2 allows a remote attacker to execute arbitrary code and obtain sensit... |
| CVE-2024-28294 | MEDIUM | 6.5 | 0.6% | Apr 29, 2024 | Limbas up to v5.2.14 was discovered to contain a SQL injection vulnerability via the ftid parameter. |
| CVE-2024-27518 | HIGH | 7.8 | 0.6% | Apr 29, 2024 | An issue in SUPERAntiSyware Professional X 10.0.1262 and 10.0.1264 allows unprivileged attackers to escalate privileges ... |
| CVE-2024-33435 | CRITICAL | 9.8 | 0.9% | Apr 29, 2024 | Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intellig... |
| CVE-2024-33276 | CRITICAL | 9.8 | 0.6% | Apr 29, 2024 | SQL Injection vulnerability in FME Modules preorderandnotication v.3.1.0 and before allows a remote attacker to run arbi... |
| CVE-2024-33272 | MEDIUM | 6.8 | 0.4% | Apr 29, 2024 | SQL injection vulnerability in KnowBand for PrestaShop autosuggest before 2.0.0 allows an attacker to run arbitrary SQL ... |
| CVE-2024-33271 | HIGH | 7.5 | 0.5% | Apr 29, 2024 | An issue in FME Modules eventsmanager before 4.4.0 allows an attacker to obtain sensitive information from the ps_custom... |
| CVE-2024-33269 | CRITICAL | 9.8 | 0.5% | Apr 29, 2024 | SQL Injection vulnerability in Prestaddons flashsales 1.9.7 and before allows an attacker to run arbitrary SQL commands ... |
| CVE-2024-33268 | CRITICAL | 9.8 | 0.5% | Apr 29, 2024 | SQL Injection vulnerability in Digincube mdgiftproduct before 1.4.1 allows an attacker to run arbitrary SQL commands via... |
| CVE-2024-33266 | CRITICAL | 9.8 | 0.7% | Apr 29, 2024 | SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary ... |
| CVE-2024-31801 | HIGH | 7.5 | 1.1% | Apr 29, 2024 | Directory Traversal vulnerability in NEXSYS-ONE before v.Rev.15320 allows a remote attacker to obtain sensitive informat... |
| CVE-2024-31747 | LOW | 2.1 | 0.3% | Apr 29, 2024 | An issue in Yealink VP59 Microsoft Teams Phone firmware 91.15.0.118 (fixed in 122.15.0.142) allows a physically proximat... |
| CVE-2024-0840 | HIGH | 8.8 | 0.9% | Apr 29, 2024 | The Grandstream UCM Series IP PBX before firmware version 1.0.20.52 is affected by a parameter injection vulnerability i... |
| CVE-2024-33443 | HIGH | 7.1 | 0.7% | Apr 29, 2024 | An issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsControll... |
| CVE-2024-33438 | HIGH | 8 | 1.1% | Apr 29, 2024 | File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted ... |
| CVE-2024-33345 | MEDIUM | 6.5 | 0.8% | Apr 29, 2024 | D-Link DIR-823G A1V1.0.2B05 was found to contain a Null-pointer dereference in the main function of upload_firmware.cgi,... |
| CVE-2024-33338 | HIGH | 7.3 | 1.0% | Apr 29, 2024 | Cross Site Scripting vulnerability in jizhicms v.2.5.4 allows a remote attacker to obtain sensitive information via a cr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now