2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0412CRITICAL9.8A vulnerability was found in DeShang DSShop up to 3.1.0. It has been declared as problematic. This vulnerability affects...
CVE-2024-0411HIGH7.5A vulnerability was found in DeShang DSMall up to 6.1.0. It has been classified as problematic. This affects an unknown ...
CVE-2024-23061CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the minute param...
CVE-2024-23060CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter...
CVE-2024-23059CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the username par...
CVE-2024-23058CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pass paramet...
CVE-2024-23057CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the tz parameter...
CVE-2024-22942CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the hostName par...
CVE-2024-0429MEDIUM5.5A denial service vulnerability has been found on  Hex Workshop affecting version 6.7, an attacker could send a command l...
CVE-2024-0252HIGH8.8ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper ...
CVE-2024-21669HIGH8.8Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and servi...
CVE-2024-21637MEDIUM5.4Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerabili...
CVE-2024-22195MEDIUM6.1Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python synt...
CVE-2024-22194LOW2.8cdo-local-uuid project provides a specialized UUID-generating function that can, on user request, cause a program to gen...
CVE-2024-22190HIGH7.8GitPython is a python library used to interact with Git repositories. There is an incomplete fix for CVE-2023-40590. On ...
CVE-2024-21667MEDIUM6.5pimcore/customer-data-framework is the Customer Management Framework for management of customer data within Pimcore. An ...
CVE-2024-21666MEDIUM6.5The Customer Management Framework (CMF) for Pimcore adds functionality for customer data management, segmentation, perso...
CVE-2024-21665MEDIUM4.3ecommerce-framework-bundle is the Pimcore Ecommerce Framework Bundle. An authenticated and unauthorized user can access ...
CVE-2024-21833HIGH8.8Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitr...
CVE-2024-21821HIGH8Multiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port o...
CVE-2024-21773HIGH8.8Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port...
CVE-2024-21638CRITICAL9.8Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azu...
CVE-2024-0333MEDIUM5.3Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged ...
CVE-2024-0395——Rejected reason: NON Security Issue.
CVE-2024-0389CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Student Attendance System 1.0. Affected i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now