2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-27661MEDIUM6.5D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allo...
CVE-2024-27660MEDIUM6.5D-Link DIR-823G A1V1.0.2B05 was discovered to contain a Null-pointer dereferences in sub_41C488(). This vulnerability al...
CVE-2024-27659MEDIUM6.5D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_42AF30(). This vulnerability allo...
CVE-2024-27658MEDIUM6.5D-Link DIR-823G A1V1.0.2B05 was discovered to contain Null-pointer dereferences in sub_4484A8(). This vulnerability allo...
CVE-2024-27657HIGH8.8D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the User-Agent parameter. This vulnerability...
CVE-2024-27656HIGH8.8D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Cookie parameter. This vulnerability all...
CVE-2024-27655HIGH8.8D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the SOAPACTION parameter. This vulnerability...
CVE-2024-26548CRITICAL9.8An issue in vivotek Network Camera v.FD8166A-VVTK-0204j allows a remote attacker to execute arbitrary code via a crafted...
CVE-2024-24246MEDIUM5.5Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count(...
CVE-2024-1595HIGH7.8Delta Electronics CNCSoft-B DOPSoft prior to v4.0.0.82 insecurely loads libraries, which may allow an attacker to use ...
CVE-2024-0068HIGH7.1Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows Fi...
CVE-2024-25180CRITICAL9.8An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf ...
CVE-2024-20765HIGH7.8Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could...
CVE-2024-2001MEDIUM5.4A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authentic...
CVE-2024-0864CRITICAL9.8Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) a...
CVE-2024-26607MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: drm/bridge: sii902x: Fix probing race issue A null...
CVE-2024-27906MEDIUM5.9Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import e...
CVE-2024-1953MEDIUM4.3Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of ro...
CVE-2024-1952MEDIUM4.3Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemer...
CVE-2024-1949LOW2.6A race condition in Mattermost versions 8.1.x before 8.1.9, and 9.4.x before 9.4.2 allows an authenticated attacker to g...
CVE-2024-1942MEDIUM4.3Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing ...
CVE-2024-1619HIGH8.8Kaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker...
CVE-2024-1888MEDIUM4.3Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member...
CVE-2024-24988MEDIUM6.5Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to s...
CVE-2024-23493MEDIUM6.5Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch de...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now