2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-46431HIGH8Tenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can e...
CVE-2024-46430MEDIUM6.5Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. Unauthorized password change via the web manageme...
CVE-2024-46429HIGH8.8A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access t...
CVE-2024-42513MEDIUM5.3Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application...
CVE-2024-42512HIGH8.6Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application...
CVE-2024-27859HIGH8.8The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14....
CVE-2024-13059HIGH7.2A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling ...
CVE-2024-13011CRITICAL9.8The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation ...
CVE-2024-13010MEDIUM6.1The WP Foodbakery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including,...
CVE-2024-10649MEDIUM6.1wandb/openui latest commit c945bb859979659add5f490a874140ad17c56a5d contains a vulnerability where unauthenticated endpo...
CVE-2024-57409MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the Parameter List module of cool-admin-java v1.0 allows attackers ...
CVE-2024-57408HIGH7.2An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute...
CVE-2024-57407HIGH7.3An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrar...
CVE-2024-54954HIGH8OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.
CVE-2024-48170MEDIUM5.4PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload injected into the name in the...
CVE-2024-57950MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Initialize denominator defaults to...
CVE-2024-12243MEDIUM5.3A flaw was found in GnuTLS, which relies on libtasn1 for ASN.1 data processing. Due to an inefficient algorithm in libta...
CVE-2024-12133MEDIUM5.3A flaw in libtasn1 causes inefficient handling of specific certificate data. When processing a large number of elements ...
CVE-2024-11831MEDIUM5.4A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not ...
CVE-2024-10334HIGH7.3A vulnerability exists in the VideONet product included in the listed System 800xA versions, where VideONet is used.  A...
CVE-2024-11621HIGH8.8Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to...
CVE-2024-8685MEDIUM4.3Path-Traversal vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability could...
CVE-2024-8684HIGH8.3OS Command Injection vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability...
CVE-2024-57949MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Don't enable interrupts in its_...
CVE-2024-13440HIGH8.2The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all v...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now