2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-50396HIGH8.8A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-50395HIGH8.8An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If...
CVE-2024-48861HIGH7.8An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerabil...
CVE-2024-38647HIGH7.5An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerabi...
CVE-2024-38644HIGH8.8An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could...
CVE-2024-37044HIGH7.2A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-37041HIGH7.2A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver...
CVE-2024-41779HIGH8.1IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security...
CVE-2024-7837HIGH8.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Firmanet Software ...
CVE-2024-11601HIGH8.1The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Slider...
CVE-2024-11104HIGH8.1The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Slider...
CVE-2024-31408HIGH8OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker...
CVE-2024-52052HIGH7.2Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom ap...
CVE-2024-51364HIGH8.8An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a...
CVE-2024-53432HIGH7.5While parsing certain malformed PLY files, PCL version 1.14.1 crashes due to an uncaught std::out_of_range exception in ...
CVE-2024-53335HIGH7.8TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi.
CVE-2024-53334HIGH8.8TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in infostat.cgi.
CVE-2024-52287HIGH7.2authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was pos...
CVE-2024-48288HIGH8TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification...
CVE-2024-48286HIGH8Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function.
CVE-2024-52799HIGH8.2Argo Workflows Chart is used to set up argo and its needed dependencies through one command. Prior to 0.44.0, the workfl...
CVE-2024-53429HIGH7.5Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.
CVE-2024-28027HIGH7.2Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies...
CVE-2024-28026HIGH7.2Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies...
CVE-2024-28025HIGH7.2Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now