2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34204 | CRITICAL | 9.8 | 1.9% | May 14, 2024 | TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the set... |
| CVE-2024-34070 | CRITICAL | 9.6 | 1.0% | May 14, 2024 | Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnera... |
| CVE-2024-33874 | CRITICAL | 9.8 | 0.9% | May 14, 2024 | HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c. |
| CVE-2024-32991 | CRITICAL | 9.8 | 0.5% | May 14, 2024 | Permission verification vulnerability in the wpa_supplicant module Impact: Successful exploitation of this vulnerability... |
| CVE-2024-32964 | CRITICAL | 9 | 54.7% | May 14, 2024 | Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system.... |
| CVE-2024-32735 | CRITICAL | 9.8 | 6.8% | May 14, 2024 | An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8... |
| CVE-2024-32700 | CRITICAL | 10 | 2.6% | May 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Kognetiks Kognetiks Chatbot for WordPress.This issue af... |
| CVE-2024-32622 | CRITICAL | 9.1 | 1.0% | May 14, 2024 | HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_ex... |
| CVE-2024-32621 | CRITICAL | 9.8 | 0.9% | May 14, 2024 | HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_... |
| CVE-2024-32615 | CRITICAL | 9.8 | 1.1% | May 14, 2024 | HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused ... |
| CVE-2024-32611 | CRITICAL | 9.8 | 1.0% | May 14, 2024 | HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c. |
| CVE-2024-31810 | CRITICAL | 9.8 | 0.6% | May 14, 2024 | TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample. |
| CVE-2024-31377 | CRITICAL | 10 | 0.5% | May 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This ... |
| CVE-2024-30802 | CRITICAL | 9.8 | 0.5% | May 14, 2024 | An issue in Vehicle Management System 7.31.0.3_20230412 allows an attacker to escalate privileges via the login.html com... |
| CVE-2024-2257 | CRITICAL | 9.1 | 1.0% | May 14, 2024 | This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to impro... |
| CVE-2024-29895 | CRITICAL | 10 | 94.4% | May 14, 2024 | Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x ... |
| CVE-2024-29212 | CRITICAL | 9.9 | 1.6% | May 14, 2024 | Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication betwe... |
| CVE-2024-29164 | CRITICAL | 9.8 | 0.9% | May 14, 2024 | HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction... |
| CVE-2024-29159 | CRITICAL | 9.8 | 0.9% | May 14, 2024 | HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instructio... |
| CVE-2024-29157 | CRITICAL | 9.8 | 0.9% | May 14, 2024 | HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer... |
| CVE-2024-28285 | CRITICAL | 9.8 | 0.5% | May 14, 2024 | A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows ... |
| CVE-2024-27280 | CRITICAL | 9.8 | 2.4% | May 14, 2024 | A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3... |
| CVE-2024-26517 | CRITICAL | 9.1 | 0.8% | May 14, 2024 | SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a ... |
| CVE-2024-23473 | CRITICAL | 9.8 | 1.1% | May 14, 2024 | The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. I... |
| CVE-2024-34257 | CRITICAL | 9.8 | 3.8% | May 8, 2024 | TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized e... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now