2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-28109 | HIGH | 8.1 | 1.0% | Mar 28, 2024 | veraPDF-library is a PDF/A validation library. Executing policy checks using custom schematron files invokes an XSL tran... |
| CVE-2024-30596 | CRITICAL | 9.8 | 0.9% | Mar 28, 2024 | Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the formSetDeviceName functi... |
| CVE-2024-30594 | MEDIUM | 6.5 | 0.5% | Mar 28, 2024 | Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter functi... |
| CVE-2024-30593 | CRITICAL | 9.8 | 0.8% | Mar 28, 2024 | Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceN... |
| CVE-2024-29896 | HIGH | 7.5 | 0.6% | Mar 28, 2024 | Astro-Shield is a library to compute the subresource integrity hashes for your JS scripts and CSS stylesheets. When auto... |
| CVE-2024-27775 | HIGH | 7.2 | 0.6% | Mar 28, 2024 | SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's ... |
| CVE-2024-30595 | CRITICAL | 9.8 | 0.8% | Mar 28, 2024 | Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the addWifiMacFilter functio... |
| CVE-2024-30422 | MEDIUM | 5.4 | 0.3% | Mar 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor ... |
| CVE-2024-30421 | MEDIUM | 4.3 | 0.2% | Mar 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a t... |
| CVE-2024-2818 | MEDIUM | 6.5 | 0.9% | Mar 28, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 befor... |
| CVE-2024-2890 | CRITICAL | 9.1 | 0.7% | Mar 28, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Tumult Inc. Tumult Hype Animations.This issue affects T... |
| CVE-2024-29241 | CRITICAL | 9.9 | 0.8% | Mar 28, 2024 | Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.... |
| CVE-2024-29240 | MEDIUM | 4.3 | 0.7% | Mar 28, 2024 | Missing authorization vulnerability in LayoutSave webapi component in Synology Surveillance Station before 9.2.0-11289 a... |
| CVE-2024-29239 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Recording.CountByC... |
| CVE-2024-29238 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log.CountByCategor... |
| CVE-2024-29237 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in ActionRule.Delete ... |
| CVE-2024-29236 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in AudioPattern.Delet... |
| CVE-2024-29235 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in IOModule.EnumLog w... |
| CVE-2024-29234 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi ... |
| CVE-2024-29233 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Emap.Delete webapi... |
| CVE-2024-29232 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Alert.Enum webapi ... |
| CVE-2024-29231 | MEDIUM | 5.4 | 0.7% | Mar 28, 2024 | Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station... |
| CVE-2024-29230 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCa... |
| CVE-2024-29229 | HIGH | 7.7 | 0.8% | Mar 28, 2024 | Missing authorization vulnerability in GetLiveViewPath webapi component in Synology Surveillance Station before 9.2.0-92... |
| CVE-2024-29228 | HIGH | 7.7 | 0.8% | Mar 28, 2024 | Missing authorization vulnerability in GetStmUrlPath webapi component in Synology Surveillance Station before 9.2.0-9289... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now