2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-28109HIGH8.1veraPDF-library is a PDF/A validation library. Executing policy checks using custom schematron files invokes an XSL tran...
CVE-2024-30596CRITICAL9.8Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the formSetDeviceName functi...
CVE-2024-30594MEDIUM6.5Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter functi...
CVE-2024-30593CRITICAL9.8Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceN...
CVE-2024-29896HIGH7.5Astro-Shield is a library to compute the subresource integrity hashes for your JS scripts and CSS stylesheets. When auto...
CVE-2024-27775HIGH7.2 SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's ...
CVE-2024-30595CRITICAL9.8Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the addWifiMacFilter functio...
CVE-2024-30422MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor ...
CVE-2024-30421MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a t...
CVE-2024-2818MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 befor...
CVE-2024-2890CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Tumult Inc. Tumult Hype Animations.This issue affects T...
CVE-2024-29241CRITICAL9.9Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9....
CVE-2024-29240MEDIUM4.3Missing authorization vulnerability in LayoutSave webapi component in Synology Surveillance Station before 9.2.0-11289 a...
CVE-2024-29239MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Recording.CountByC...
CVE-2024-29238MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log.CountByCategor...
CVE-2024-29237MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in ActionRule.Delete ...
CVE-2024-29236MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in AudioPattern.Delet...
CVE-2024-29235MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in IOModule.EnumLog w...
CVE-2024-29234MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi ...
CVE-2024-29233MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Emap.Delete webapi...
CVE-2024-29232MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Alert.Enum webapi ...
CVE-2024-29231MEDIUM5.4Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station...
CVE-2024-29230MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCa...
CVE-2024-29229HIGH7.7Missing authorization vulnerability in GetLiveViewPath webapi component in Synology Surveillance Station before 9.2.0-92...
CVE-2024-29228HIGH7.7Missing authorization vulnerability in GetStmUrlPath webapi component in Synology Surveillance Station before 9.2.0-9289...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now