2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32881 | CRITICAL | 9.8 | 0.8% | Apr 26, 2024 | Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access ... |
| CVE-2024-31601 | CRITICAL | 9.8 | 0.4% | Apr 26, 2024 | An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v. 20240323 and before allows a... |
| CVE-2024-25343 | CRITICAL | 9.1 | 0.5% | Apr 26, 2024 | Tenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords. |
| CVE-2024-33344 | CRITICAL | 9.8 | 19.9% | Apr 26, 2024 | D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows r... |
| CVE-2024-32766 | CRITICAL | 10 | 2.3% | Apr 26, 2024 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
| CVE-2024-32764 | CRITICAL | 9.9 | 0.4% | Apr 26, 2024 | A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited,... |
| CVE-2024-0740 | CRITICAL | 9.8 | 1.2% | Apr 26, 2024 | Eclipse Target Management: Terminal and Remote System Explorer (RSE) version <= 4.5.400 has a remote code execution vuln... |
| CVE-2024-3962 | CRITICAL | 9.8 | 1.4% | Apr 26, 2024 | The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing ... |
| CVE-2024-22633 | CRITICAL | 9.8 | 0.9% | Apr 26, 2024 | Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (... |
| CVE-2024-22632 | CRITICAL | 9.8 | 1.0% | Apr 26, 2024 | Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (... |
| CVE-2024-33668 | CRITICAL | 9.1 | 0.4% | Apr 26, 2024 | An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to id... |
| CVE-2024-33661 | CRITICAL | 9.1 | 0.6% | Apr 26, 2024 | Portainer before 2.20.0 allows redirects when the target is not index.yaml. |
| CVE-2024-32651 | CRITICAL | 10 | 83.7% | Apr 26, 2024 | changedetection.io is an open source web page change detection, website watcher, restock monitor and notification servic... |
| CVE-2024-0916 | CRITICAL | 10 | 1.0% | Apr 25, 2024 | Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3.... |
| CVE-2024-31615 | CRITICAL | 9.8 | 0.7% | Apr 25, 2024 | ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php. |
| CVE-2024-22391 | CRITICAL | 9.8 | 1.4% | Apr 25, 2024 | A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroo... |
| CVE-2024-22373 | CRITICAL | 9.8 | 1.5% | Apr 25, 2024 | An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malater... |
| CVE-2024-4165 | CRITICAL | 9.8 | 1.5% | Apr 25, 2024 | A vulnerability, which was classified as critical, was found in Tenda G3 15.11.0.17(9502). Affected is the function modi... |
| CVE-2024-4164 | CRITICAL | 9.8 | 1.5% | Apr 25, 2024 | A vulnerability, which was classified as critical, has been found in Tenda G3 15.11.0.17(9502). This issue affects the f... |
| CVE-2024-31266 | CRITICAL | 9.1 | 0.7% | Apr 25, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in AlgolPlus Advanced Order Export For WooCommer... |
| CVE-2024-30560 | CRITICAL | 9.6 | 0.3% | Apr 25, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in 大侠WP DX-Watermark.This issue affects DX-Watermark: from n/a through 1... |
| CVE-2024-22144 | CRITICAL | 9 | 0.9% | Apr 25, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Eli Scheetz Anti-Malware Security and Brute-F... |
| CVE-2024-4173 | CRITICAL | 9.8 | 0.6% | Apr 25, 2024 | A vulnerability in Brocade SANnav exposes Kafka in the wan interface. The vulnerability could allow an unauthenticated... |
| CVE-2024-28825 | CRITICAL | 9.8 | 0.5% | Apr 24, 2024 | Improper restriction of excessive authentication attempts on some authentication methods in Checkmk before 2.3.0b5 (beta... |
| CVE-2024-32954 | CRITICAL | 9.1 | 0.6% | Apr 24, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Tribulant Newsletters.This issue affects Newsletters: f... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now