2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21649 | HIGH | 8.8 | 1.3% | Jan 30, 2024 | The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Mul... |
| CVE-2024-1035 | CRITICAL | 9.8 | 0.8% | Jan 30, 2024 | A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function... |
| CVE-2024-1019 | HIGH | 8.6 | 0.7% | Jan 30, 2024 | ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially... |
| CVE-2024-24333 | CRITICAL | 9.8 | 1.7% | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc paramet... |
| CVE-2024-24332 | CRITICAL | 9.8 | 1.7% | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url paramete... |
| CVE-2024-24331 | CRITICAL | 9.8 | 1.6% | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param... |
| CVE-2024-24330 | CRITICAL | 9.8 | 1.5% | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enab... |
| CVE-2024-24329 | CRITICAL | 9.8 | 6.2% | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param... |
| CVE-2024-24328 | CRITICAL | 9.8 | 6.2% | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param... |
| CVE-2024-24327 | CRITICAL | 9.8 | 1.6% | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass pa... |
| CVE-2024-24326 | CRITICAL | 9.8 | 1.6% | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable pa... |
| CVE-2024-24325 | CRITICAL | 9.8 | 1.7% | Jan 30, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param... |
| CVE-2024-24324 | CRITICAL | 9.8 | 0.7% | Jan 30, 2024 | TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow. |
| CVE-2024-1034 | CRITICAL | 9.8 | 0.8% | Jan 30, 2024 | A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadFile... |
| CVE-2024-0564 | MEDIUM | 6.5 | 0.6% | Jan 30, 2024 | A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (... |
| CVE-2024-1033 | HIGH | 7.5 | 0.6% | Jan 30, 2024 | A vulnerability, which was classified as problematic, has been found in openBI up to 1.0.8. Affected by this issue is th... |
| CVE-2024-1032 | CRITICAL | 9.8 | 0.8% | Jan 30, 2024 | A vulnerability classified as critical was found in openBI up to 1.0.8. Affected by this vulnerability is the function t... |
| CVE-2024-1031 | MEDIUM | 6.1 | 0.4% | Jan 30, 2024 | A vulnerability was found in CodeAstro Expense Management System 1.0. It has been declared as problematic. This vulnerab... |
| CVE-2024-0676 | HIGH | 7.1 | 0.1% | Jan 30, 2024 | Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a lo... |
| CVE-2024-0675 | MEDIUM | 6.8 | 0.2% | Jan 30, 2024 | Vulnerability of improper checking for unusual or exceptional conditions in Lamassu Bitcoin ATM Douro machines, in its ... |
| CVE-2024-0674 | HIGH | 7.8 | 0.1% | Jan 30, 2024 | Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local ... |
| CVE-2024-22894 | MEDIUM | 6.8 | 0.7% | Jan 30, 2024 | An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novel... |
| CVE-2024-1063 | HIGH | 7.5 | 0.4% | Jan 30, 2024 | Appwrite <= v1.4.13 is affected by a Server-Side Request Forgery (SSRF) via the '/v1/avatars/favicon' endpoint due to an... |
| CVE-2024-1030 | MEDIUM | 5.4 | 0.4% | Jan 30, 2024 | A vulnerability was found in Cogites eReserv 7.7.58. It has been classified as problematic. This affects an unknown part... |
| CVE-2024-22523 | HIGH | 7.5 | 1.1% | Jan 30, 2024 | Directory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now