2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32881 | CRITICAL | 9.8 | 0.8% | Apr 26, 2024 | Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access ... |
| CVE-2024-32878 | HIGH | 8.8 | 0.7% | Apr 26, 2024 | Llama.cpp is LLM inference in C/C++. There is a use of uninitialized heap variable vulnerability in gguf_init_from_file,... |
| CVE-2024-31601 | CRITICAL | 9.8 | 0.4% | Apr 26, 2024 | An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v. 20240323 and before allows a... |
| CVE-2024-31502 | HIGH | 8.1 | 0.6% | Apr 26, 2024 | An issue in Insurance Management System v.1.0.0 and before allows a remote attacker to escalate privileges via a crafted... |
| CVE-2024-4238 | HIGH | 8.8 | 1.5% | Apr 26, 2024 | A vulnerability has been found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this vulnerability is the... |
| CVE-2024-28326 | MEDIUM | 6.8 | 0.3% | Apr 26, 2024 | Incorrect Access Control in ASUS RT-N12+ B1 and RT-N12 D1 routers allows local attackers to obtain root terminal access ... |
| CVE-2024-25343 | CRITICAL | 9.1 | 0.5% | Apr 26, 2024 | Tenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords. |
| CVE-2024-4237 | HIGH | 8.8 | 1.5% | Apr 26, 2024 | A vulnerability, which was classified as critical, was found in Tenda AX1806 1.0.0.1. Affected is the function R7WebsSec... |
| CVE-2024-28327 | HIGH | 8.4 | 0.1% | Apr 26, 2024 | Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized acce... |
| CVE-2024-28325 | MEDIUM | 6.1 | 0.1% | Apr 26, 2024 | Asus RT-N12+ B1 router stores credentials in cleartext, which could allow local attackers to obtain unauthorized access ... |
| CVE-2024-4236 | HIGH | 8.8 | 14.9% | Apr 26, 2024 | A vulnerability, which was classified as critical, has been found in Tenda AX1803 1.0.0.1. This issue affects the functi... |
| CVE-2024-4235 | MEDIUM | 4.9 | 0.6% | Apr 26, 2024 | A vulnerability classified as problematic was found in Netgear DG834Gv5 1.6.01.34. This vulnerability affects unknown co... |
| CVE-2024-33344 | CRITICAL | 9.8 | 19.9% | Apr 26, 2024 | D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows r... |
| CVE-2024-33343 | HIGH | 8.8 | 8.3% | Apr 26, 2024 | D-Link DIR-822+ V1.0.5 was found to contain a command injection in ChgSambaUserSettings function of prog.cgi, which allo... |
| CVE-2024-33342 | HIGH | 7.5 | 1.6% | Apr 26, 2024 | D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows r... |
| CVE-2024-32884 | MEDIUM | 6.4 | 0.5% | Apr 26, 2024 | gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that t... |
| CVE-2024-32880 | HIGH | 7.2 | 1.3% | Apr 26, 2024 | pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder a... |
| CVE-2024-33260 | MEDIUM | 5.1 | 0.2% | Apr 26, 2024 | Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component parser_parse_class at je... |
| CVE-2024-33259 | MEDIUM | 5.5 | 0.3% | Apr 26, 2024 | Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component scanner_seek at jerry-co... |
| CVE-2024-33258 | HIGH | 7.1 | 0.3% | Apr 26, 2024 | Jerryscript commit ff9ff8f was discovered to contain a segmentation violation via the component vm_loop at jerry-core/vm... |
| CVE-2024-33255 | MEDIUM | 6.2 | 0.3% | Apr 26, 2024 | Jerryscript commit cefd391 was discovered to contain an Assertion Failure via ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p... |
| CVE-2024-32766 | CRITICAL | 10 | 2.3% | Apr 26, 2024 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
| CVE-2024-32764 | CRITICAL | 9.9 | 0.4% | Apr 26, 2024 | A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited,... |
| CVE-2024-28328 | MEDIUM | 5.4 | 0.4% | Apr 26, 2024 | CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formul... |
| CVE-2024-27124 | HIGH | 7.5 | 1.4% | Apr 26, 2024 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now