2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-38409HIGH7.8Memory corruption while station LL statistic handling.
CVE-2024-38407HIGH7Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.
CVE-2024-38406HIGH7Memory corruption while handling IOCTL calls in JPEG Encoder driver.
CVE-2024-33033HIGH7.8Memory corruption while processing IOCTL calls to unmap the buffers.
CVE-2024-10760HIGH7.5A vulnerability was found in code-projects University Event Management System 1.0 and classified as critical. This issue...
CVE-2024-10759HIGH8.8A vulnerability has been found in itsourcecode Farm Management System 1.0 and classified as critical. This vulnerability...
CVE-2024-20104HIGH8.4In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pri...
CVE-2024-10749HIGH8.1A vulnerability, which was classified as critical, was found in ThinkAdmin up to 6.1.67. Affected is the function script...
CVE-2024-10742HIGH7.5A vulnerability was found in code-projects Wazifa System 1.0 and classified as critical. This issue affects some unknown...
CVE-2024-51774HIGH8.1qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.
CVE-2024-9191HIGH7.8The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessP...
CVE-2024-48353HIGH7.5Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and ...
CVE-2024-51492HIGH8.8Zusam is a free and open-source way to self-host private forums. Prior to version 0.5.6, specially crafted SVG files upl...
CVE-2024-51248HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51247HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51245HIGH8.8In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51244HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-49770HIGH7.7`oak` is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers a...
CVE-2024-48352HIGH7.5Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTT...
CVE-2024-48217HIGH8.8An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-p...
CVE-2024-41744HIGH8.8IBM CICS TX Standard 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious...
CVE-2024-40490HIGH7.5An issue in Sourcebans++ before v.1.8.0 allows a remote attacker to obtain sensitive information via a crafted XAJAX cal...
CVE-2024-22733HIGH7.5TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration ...
CVE-2024-10662HIGH8.8A vulnerability was found in Tenda AC15 15.03.05.19 and classified as critical. This issue affects the function formSetD...
CVE-2024-10661HIGH8.8A vulnerability has been found in Tenda AC15 15.03.05.19 and classified as critical. This vulnerability affects the func...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now