2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-57542HIGH8.8Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_bt...
CVE-2024-57541MEDIUM5.5Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (ipv6_protect_s...
CVE-2024-57540MEDIUM6.5Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (action) is cop...
CVE-2024-57539HIGH8.2Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via userEmail.
CVE-2024-57538MEDIUM6.5Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (anonymous_prot...
CVE-2024-57537MEDIUM6.3Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (page) is copie...
CVE-2024-57536HIGH8Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via wizard_status.
CVE-2024-57360MEDIUM5.5https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: ...
CVE-2024-55959CRITICAL9.1Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.
CVE-2024-55958MEDIUM4.8Northern.tech CFEngine Enterprise Mission Portal 3.24.0, 3.21.5, and below allows XSS. The fixed versions are 3.24.1 and...
CVE-2024-48392MEDIUM5.4OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into u...
CVE-2024-21245MEDIUM5.4Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). ...
CVE-2024-42936CRITICAL9.8The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Ex...
CVE-2024-55504MEDIUM5.5An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially ...
CVE-2024-51417MEDIUM6.4An issue in System.Linq.Dynamic.Core before 1.6.0 allows remote access to properties on reflection types and static prop...
CVE-2024-54795MEDIUM5.4SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the works...
CVE-2024-54794CRITICAL9.1The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
CVE-2024-54792MEDIUM6.1A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An ...
CVE-2024-45687LOW2.4Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in Payara Pl...
CVE-2024-57036HIGH8.1TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main f...
CVE-2024-56990MEDIUM4.5PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /view-medhistory.php and /admin...
CVE-2024-56998MEDIUM4.2PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /edit-profile.php via the param...
CVE-2024-56997MEDIUM4.2PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /doctor/index.php via the 'Emai...
CVE-2024-53829HIGH8.2CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ...
CVE-2024-56277MEDIUM5.3Improper Encoding or Escaping of Output vulnerability in Ays Pro Poll Maker poll-maker.This issue affects Poll Maker: fr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now