2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-32881CRITICAL9.8Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access ...
CVE-2024-32878HIGH8.8Llama.cpp is LLM inference in C/C++. There is a use of uninitialized heap variable vulnerability in gguf_init_from_file,...
CVE-2024-31601CRITICAL9.8An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v. 20240323 and before allows a...
CVE-2024-31502HIGH8.1An issue in Insurance Management System v.1.0.0 and before allows a remote attacker to escalate privileges via a crafted...
CVE-2024-4238HIGH8.8A vulnerability has been found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this vulnerability is the...
CVE-2024-28326MEDIUM6.8Incorrect Access Control in ASUS RT-N12+ B1 and RT-N12 D1 routers allows local attackers to obtain root terminal access ...
CVE-2024-25343CRITICAL9.1Tenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords.
CVE-2024-4237HIGH8.8A vulnerability, which was classified as critical, was found in Tenda AX1806 1.0.0.1. Affected is the function R7WebsSec...
CVE-2024-28327HIGH8.4Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized acce...
CVE-2024-28325MEDIUM6.1Asus RT-N12+ B1 router stores credentials in cleartext, which could allow local attackers to obtain unauthorized access ...
CVE-2024-4236HIGH8.8A vulnerability, which was classified as critical, has been found in Tenda AX1803 1.0.0.1. This issue affects the functi...
CVE-2024-4235MEDIUM4.9A vulnerability classified as problematic was found in Netgear DG834Gv5 1.6.01.34. This vulnerability affects unknown co...
CVE-2024-33344CRITICAL9.8D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows r...
CVE-2024-33343HIGH8.8D-Link DIR-822+ V1.0.5 was found to contain a command injection in ChgSambaUserSettings function of prog.cgi, which allo...
CVE-2024-33342HIGH7.5D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows r...
CVE-2024-32884MEDIUM6.4gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that t...
CVE-2024-32880HIGH7.2pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder a...
CVE-2024-33260MEDIUM5.1Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component parser_parse_class at je...
CVE-2024-33259MEDIUM5.5Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component scanner_seek at jerry-co...
CVE-2024-33258HIGH7.1Jerryscript commit ff9ff8f was discovered to contain a segmentation violation via the component vm_loop at jerry-core/vm...
CVE-2024-33255MEDIUM6.2Jerryscript commit cefd391 was discovered to contain an Assertion Failure via ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p...
CVE-2024-32766CRITICAL10An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2024-32764CRITICAL9.9A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited,...
CVE-2024-28328MEDIUM5.4CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formul...
CVE-2024-27124HIGH7.5An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now