2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25735 | CRITICAL | 9.1 | 50.6% | Mar 27, 2024 | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext password... |
| CVE-2024-25393 | CRITICAL | 9.8 | 1.1% | Mar 27, 2024 | A stack buffer overflow occurs in net/at/src/at_server.c in RT-Thread through 5.0.2. |
| CVE-2024-2934 | CRITICAL | 9.8 | 0.8% | Mar 27, 2024 | A vulnerability classified as critical was found in SourceCodester Todo List in Kanban Board 1.0. Affected by this vulne... |
| CVE-2024-2930 | CRITICAL | 9.8 | 1.2% | Mar 27, 2024 | A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been declared as critical. Affected by this v... |
| CVE-2024-2927 | CRITICAL | 9.8 | 0.8% | Mar 26, 2024 | A vulnerability was found in code-projects Mobile Shop 1.0. It has been classified as critical. Affected is an unknown f... |
| CVE-2024-2917 | CRITICAL | 9.8 | 0.8% | Mar 26, 2024 | A vulnerability was found in Campcodes House Rental Management System 1.0. It has been declared as critical. Affected by... |
| CVE-2024-28545 | CRITICAL | 9.8 | 2.3% | Mar 26, 2024 | Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter of formsetUsbUnload func... |
| CVE-2024-25421 | CRITICAL | 9.8 | 1.7% | Mar 26, 2024 | An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CAC... |
| CVE-2024-2921 | CRITICAL | 9.8 | 0.8% | Mar 26, 2024 | Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated u... |
| CVE-2024-2452 | CRITICAL | 9.8 | 0.9% | Mar 26, 2024 | In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cau... |
| CVE-2024-29401 | CRITICAL | 9.8 | 0.8% | Mar 26, 2024 | xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted a... |
| CVE-2024-29684 | CRITICAL | 9.8 | 0.6% | Mar 26, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage... |
| CVE-2024-28048 | CRITICAL | 9.8 | 1.3% | Mar 26, 2024 | OS command injection vulnerability exists in ffBull ver.4.11, which may allow a remote unauthenticated attacker to execu... |
| CVE-2024-29303 | CRITICAL | 9.8 | 0.9% | Mar 26, 2024 | The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection |
| CVE-2024-28421 | CRITICAL | 9.8 | 0.8% | Mar 25, 2024 | SQL Injection vulnerability in Razor 0.8.0 allows a remote attacker to escalate privileges via the ChannelModel::updatea... |
| CVE-2024-0901 | CRITICAL | 9.1 | 0.7% | Mar 25, 2024 | Remotely executed SEGV and out of bounds read allows malicious packet sender to crash or cause an out of bounds read via... |
| CVE-2024-2873 | CRITICAL | 9.1 | 0.6% | Mar 25, 2024 | A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create... |
| CVE-2024-29666 | CRITICAL | 9.8 | 0.7% | Mar 25, 2024 | Insecure Permissions vulnerability in Vehicle Monitoring platform system CMSV6 v.7.31.0.2 through v.7.32.0.3 allows a re... |
| CVE-2024-29650 | CRITICAL | 9.8 | 1.4% | Mar 25, 2024 | An issue in @thi.ng/paths v.5.1.62 and before allows a remote attacker to execute arbitrary code via the mutIn and mutIn... |
| CVE-2024-2865 | CRITICAL | 9.8 | 0.6% | Mar 25, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Qu... |
| CVE-2024-28393 | CRITICAL | 9.8 | 0.7% | Mar 25, 2024 | SQL injection vulnerability in scalapay v.1.2.41 and before allows a remote attacker to escalate privileges via the Scal... |
| CVE-2024-28386 | CRITICAL | 9.8 | 1.5% | Mar 25, 2024 | An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getP... |
| CVE-2024-2863 | CRITICAL | 9.8 | 67.0% | Mar 25, 2024 | This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant. |
| CVE-2024-2862 | CRITICAL | 9.8 | 51.3% | Mar 25, 2024 | This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affect... |
| CVE-2024-2856 | CRITICAL | 9.8 | 1.2% | Mar 24, 2024 | A vulnerability, which was classified as critical, has been found in Tenda AC10 16.03.10.13/16.03.10.20. Affected by thi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now