2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-21649HIGH8.8The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Mul...
CVE-2024-1035CRITICAL9.8A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function...
CVE-2024-1019HIGH8.6ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially...
CVE-2024-24333CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc paramet...
CVE-2024-24332CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url paramete...
CVE-2024-24331CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param...
CVE-2024-24330CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enab...
CVE-2024-24329CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param...
CVE-2024-24328CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param...
CVE-2024-24327CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass pa...
CVE-2024-24326CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable pa...
CVE-2024-24325CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param...
CVE-2024-24324CRITICAL9.8TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.
CVE-2024-1034CRITICAL9.8A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadFile...
CVE-2024-0564MEDIUM6.5A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (...
CVE-2024-1033HIGH7.5A vulnerability, which was classified as problematic, has been found in openBI up to 1.0.8. Affected by this issue is th...
CVE-2024-1032CRITICAL9.8A vulnerability classified as critical was found in openBI up to 1.0.8. Affected by this vulnerability is the function t...
CVE-2024-1031MEDIUM6.1A vulnerability was found in CodeAstro Expense Management System 1.0. It has been declared as problematic. This vulnerab...
CVE-2024-0676HIGH7.1Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a lo...
CVE-2024-0675MEDIUM6.8Vulnerability of improper checking for unusual or exceptional conditions in Lamassu Bitcoin ATM Douro machines, in its ...
CVE-2024-0674HIGH7.8Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local ...
CVE-2024-22894MEDIUM6.8An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novel...
CVE-2024-1063HIGH7.5Appwrite <= v1.4.13 is affected by a Server-Side Request Forgery (SSRF) via the '/v1/avatars/favicon' endpoint due to an...
CVE-2024-1030MEDIUM5.4A vulnerability was found in Cogites eReserv 7.7.58. It has been classified as problematic. This affects an unknown part...
CVE-2024-22523HIGH7.5Directory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now