2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0339Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-0198Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-11890Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-57178MEDIUM5.9An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' pa...
CVE-2024-57177HIGH7.3A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially ...
CVE-2024-8550HIGH7.5A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4...
CVE-2024-54658MEDIUM6.5The issue was addressed with improved memory handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, mac...
CVE-2024-46437MEDIUM6.5A sensitive information disclosure vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an unau...
CVE-2024-46436HIGH8.3Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the ...
CVE-2024-46435HIGH8A stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote a...
CVE-2024-46434HIGH8.8Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized rem...
CVE-2024-46433HIGH8.8A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the...
CVE-2024-46432HIGH8.8Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POS...
CVE-2024-46431HIGH8Tenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can e...
CVE-2024-46430MEDIUM6.5Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web manageme...
CVE-2024-46429HIGH8.8A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access t...
CVE-2024-42513MEDIUM5.3Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application...
CVE-2024-42512HIGH8.6Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application...
CVE-2024-27859HIGH8.8The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14....
CVE-2024-13059HIGH7.2A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling ...
CVE-2024-13011CRITICAL9.8The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation ...
CVE-2024-13010MEDIUM6.1The WP Foodbakery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,...
CVE-2024-10649MEDIUM6.1wandb/openui latest commit c945bb859979659add5f490a874140ad17c56a5d contains a vulnerability where unauthenticated endpo...
CVE-2024-57409MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers ...
CVE-2024-57408HIGH7.2An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now