2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50396 | HIGH | 8.8 | 0.6% | Nov 22, 2024 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2024-50395 | HIGH | 8.8 | 1.3% | Nov 22, 2024 | An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If... |
| CVE-2024-48861 | HIGH | 7.8 | 0.8% | Nov 22, 2024 | An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerabil... |
| CVE-2024-38647 | HIGH | 7.5 | 0.6% | Nov 22, 2024 | An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerabi... |
| CVE-2024-38644 | HIGH | 8.8 | 1.6% | Nov 22, 2024 | An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could... |
| CVE-2024-37044 | HIGH | 7.2 | 0.8% | Nov 22, 2024 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2024-37041 | HIGH | 7.2 | 0.8% | Nov 22, 2024 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2024-41779 | HIGH | 8.1 | 0.8% | Nov 22, 2024 | IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security... |
| CVE-2024-7837 | HIGH | 8.2 | 0.4% | Nov 22, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Firmanet Software ... |
| CVE-2024-11601 | HIGH | 8.1 | 0.3% | Nov 22, 2024 | The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Slider... |
| CVE-2024-11104 | HIGH | 8.1 | 0.7% | Nov 22, 2024 | The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Slider... |
| CVE-2024-31408 | HIGH | 8 | 1.1% | Nov 22, 2024 | OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker... |
| CVE-2024-52052 | HIGH | 7.2 | 0.5% | Nov 21, 2024 | Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom ap... |
| CVE-2024-51364 | HIGH | 8.8 | 0.7% | Nov 21, 2024 | An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a... |
| CVE-2024-53432 | HIGH | 7.5 | 0.7% | Nov 21, 2024 | While parsing certain malformed PLY files, PCL version 1.14.1 crashes due to an uncaught std::out_of_range exception in ... |
| CVE-2024-53335 | HIGH | 7.8 | 0.3% | Nov 21, 2024 | TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi. |
| CVE-2024-53334 | HIGH | 8.8 | 0.7% | Nov 21, 2024 | TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in infostat.cgi. |
| CVE-2024-52287 | HIGH | 7.2 | 0.6% | Nov 21, 2024 | authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was pos... |
| CVE-2024-48288 | HIGH | 8 | 10.3% | Nov 21, 2024 | TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification... |
| CVE-2024-48286 | HIGH | 8 | 12.4% | Nov 21, 2024 | Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function. |
| CVE-2024-52799 | HIGH | 8.2 | 0.2% | Nov 21, 2024 | Argo Workflows Chart is used to set up argo and its needed dependencies through one command. Prior to 0.44.0, the workfl... |
| CVE-2024-53429 | HIGH | 7.5 | 0.7% | Nov 21, 2024 | Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash. |
| CVE-2024-28027 | HIGH | 7.2 | 7.5% | Nov 21, 2024 | Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies... |
| CVE-2024-28026 | HIGH | 7.2 | 5.8% | Nov 21, 2024 | Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies... |
| CVE-2024-28025 | HIGH | 7.2 | 7.5% | Nov 21, 2024 | Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now