2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29973 | CRITICAL | 9.8 | 86.2% | Jun 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar... |
| CVE-2024-29972 | CRITICAL | 9.8 | 89.2% | Jun 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326... |
| CVE-2024-36782 | CRITICAL | 9.8 | 0.4% | Jun 3, 2024 | TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, whic... |
| CVE-2024-36783 | CRITICAL | 9.8 | 1.4% | Jun 3, 2024 | TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the N... |
| CVE-2024-34987 | CRITICAL | 9.1 | 0.6% | Jun 3, 2024 | A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2... |
| CVE-2024-31682 | CRITICAL | 9.8 | 0.5% | Jun 3, 2024 | Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attac... |
| CVE-2024-4332 | CRITICAL | 9.3 | 0.6% | Jun 3, 2024 | An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (T... |
| CVE-2024-37019 | CRITICAL | 9.8 | 0.6% | Jun 3, 2024 | Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication. |
| CVE-2024-5197 | CRITICAL | 9.1 | 0.8% | Jun 3, 2024 | There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the... |
| CVE-2024-36568 | CRITICAL | 9.8 | 0.5% | Jun 3, 2024 | Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=. |
| CVE-2024-0336 | CRITICAL | 9.4 | 0.4% | Jun 3, 2024 | Missing Authentication for Critical Function vulnerability in EMTA Grup PDKS allows Exploiting Incorrectly Configured Ac... |
| CVE-2024-3829 | CRITICAL | 9.1 | 0.9% | Jun 3, 2024 | qdrant/qdrant version 1.9.0-dev is vulnerable to arbitrary file read and write during the snapshot recovery process. Att... |
| CVE-2024-5404 | CRITICAL | 9.8 | 0.5% | Jun 3, 2024 | An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mech... |
| CVE-2024-5311 | CRITICAL | 9.8 | 0.6% | Jun 3, 2024 | DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbit... |
| CVE-2024-36042 | CRITICAL | 9.8 | 0.9% | Jun 3, 2024 | Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often prov... |
| CVE-2024-20067 | CRITICAL | 9.8 | 0.7% | Jun 3, 2024 | In modem, there is a possible out of bounds write due to improper input invalidation. This could lead to remote denial o... |
| CVE-2024-5590 | CRITICAL | 9.8 | 0.6% | Jun 3, 2024 | A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. This v... |
| CVE-2024-5589 | CRITICAL | 9.8 | 0.5% | Jun 3, 2024 | A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This... |
| CVE-2024-36389 | CRITICAL | 9.8 | 0.5% | Jun 2, 2024 | MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass |
| CVE-2024-36388 | CRITICAL | 9.8 | 0.5% | Jun 2, 2024 | MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function |
| CVE-2024-27776 | CRITICAL | 9.8 | 0.6% | Jun 2, 2024 | MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow ... |
| CVE-2024-3820 | CRITICAL | 10 | 0.7% | Jun 1, 2024 | The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to SQL ... |
| CVE-2024-33999 | CRITICAL | 9.8 | 0.5% | May 31, 2024 | The referrer URL used by MFA required additional sanitizing, rather than being used directly. |
| CVE-2024-5176 | CRITICAL | 9.4 | 0.5% | May 31, 2024 | Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services wi... |
| CVE-2024-31030 | CRITICAL | 9.1 | 0.8% | May 31, 2024 | An issue in coap_msg.c in Keith Cullen's FreeCoAP v.0.7 allows remote attackers to cause a Denial of Service or potentia... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now