2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0412 | CRITICAL | 9.8 | 0.8% | Jan 11, 2024 | A vulnerability was found in DeShang DSShop up to 3.1.0. It has been declared as problematic. This vulnerability affects... |
| CVE-2024-0411 | HIGH | 7.5 | 2.2% | Jan 11, 2024 | A vulnerability was found in DeShang DSMall up to 6.1.0. It has been classified as problematic. This affects an unknown ... |
| CVE-2024-23061 | CRITICAL | 9.8 | 1.7% | Jan 11, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the minute param... |
| CVE-2024-23060 | CRITICAL | 9.8 | 1.7% | Jan 11, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter... |
| CVE-2024-23059 | CRITICAL | 9.8 | 1.7% | Jan 11, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the username par... |
| CVE-2024-23058 | CRITICAL | 9.8 | 1.7% | Jan 11, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass paramet... |
| CVE-2024-23057 | CRITICAL | 9.8 | 1.6% | Jan 11, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the tz parameter... |
| CVE-2024-22942 | CRITICAL | 9.8 | 1.6% | Jan 11, 2024 | TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the hostName par... |
| CVE-2024-0429 | MEDIUM | 5.5 | 0.2% | Jan 11, 2024 | A denial service vulnerability has been found on Hex Workshop affecting version 6.7, an attacker could send a command l... |
| CVE-2024-0252 | HIGH | 8.8 | 7.8% | Jan 11, 2024 | ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper ... |
| CVE-2024-21669 | HIGH | 8.8 | 0.6% | Jan 11, 2024 | Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and servi... |
| CVE-2024-21637 | MEDIUM | 5.4 | 0.5% | Jan 11, 2024 | Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerabili... |
| CVE-2024-22195 | MEDIUM | 6.1 | 0.9% | Jan 11, 2024 | Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python synt... |
| CVE-2024-22194 | LOW | 2.8 | 0.4% | Jan 11, 2024 | cdo-local-uuid project provides a specialized UUID-generating function that can, on user request, cause a program to gen... |
| CVE-2024-22190 | HIGH | 7.8 | 0.3% | Jan 11, 2024 | GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On ... |
| CVE-2024-21667 | MEDIUM | 6.5 | 0.6% | Jan 11, 2024 | pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An ... |
| CVE-2024-21666 | MEDIUM | 6.5 | 0.6% | Jan 11, 2024 | The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, perso... |
| CVE-2024-21665 | MEDIUM | 4.3 | 0.5% | Jan 11, 2024 | ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access ... |
| CVE-2024-21833 | HIGH | 8.8 | 1.1% | Jan 11, 2024 | Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitr... |
| CVE-2024-21821 | HIGH | 8 | 0.4% | Jan 11, 2024 | Multiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port o... |
| CVE-2024-21773 | HIGH | 8.8 | 0.5% | Jan 11, 2024 | Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port... |
| CVE-2024-21638 | CRITICAL | 9.8 | 1.7% | Jan 10, 2024 | Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azu... |
| CVE-2024-0333 | MEDIUM | 5.3 | 0.4% | Jan 10, 2024 | Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged ... |
| CVE-2024-0395 | — | — | — | Jan 10, 2024 | Rejected reason: NON Security Issue. |
| CVE-2024-0389 | CRITICAL | 9.8 | 0.8% | Jan 10, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Student Attendance System 1.0. Affected i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now