2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-45885HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...
CVE-2024-45884HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...
CVE-2024-45882HIGH8DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parame...
CVE-2024-51672HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper Better...
CVE-2024-51582HIGH8.8Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion...
CVE-2024-51253HIGH8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51251HIGH8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51249HIGH8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51246HIGH8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-50530HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Stars SMTP Mailer stars-smtp-mailer al...
CVE-2024-50529HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in rudrainn Training – Courses training allows Upload a We...
CVE-2024-50528HIGH7.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Bui...
CVE-2024-45164HIGH7.1Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the la...
CVE-2024-51561HIGH7.5This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. A...
CVE-2024-36485HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.
CVE-2024-51661HIGH7.2Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingre...
CVE-2024-48878HIGH8.8Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.
CVE-2024-10389HIGH7.5There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). ...
CVE-2024-38424HIGH7.8Memory corruption during GNSS HAL process initialization.
CVE-2024-38423HIGH7.8Memory corruption while processing GPU page table switch.
CVE-2024-38422HIGH7.8Memory corruption while processing voice packet with arbitrary data received from ADSP.
CVE-2024-38421HIGH7.8Memory corruption while processing GPU commands.
CVE-2024-38419HIGH7.8Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.
CVE-2024-38415HIGH7.8Memory corruption while handling session errors from firmware.
CVE-2024-38410HIGH7.8Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now