2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34579HIGH8.5Fuji Electric Alpha5 SMART is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbi...
CVE-2024-57785MEDIUM4.9Zenitel AlphaWeb XE v11.2.3.10 was discovered to contain a local file inclusion vulnerability via the component amc_uplo...
CVE-2024-57784MEDIUM5.5An issue in the component /php/script_uploads.php of Zenitel AlphaWeb XE v11.2.3.10 allows attackers to execute a direct...
CVE-2024-57704HIGH8.8Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi...
CVE-2024-57703CRITICAL9.8Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi...
CVE-2024-56144MEDIUM5.4librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on t...
CVE-2024-53553CRITICAL9.1An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web reque...
CVE-2024-40514MEDIUM4.6Insecure Permissions vulnerability in themesebrand Chatvia v.5.3.2 allows a remote attacker to escalate privileges via t...
CVE-2024-40513MEDIUM4.6An issue in themesebrand Chatvia v.5.3.2 allows a remote attacker to execute arbitrary code via the User profile Upload ...
CVE-2024-55511HIGH7.8A null pointer dereference vulnerability in Macrium Reflect prior to 8.1.8017 allows a local attacker to cause a system ...
CVE-2024-54660HIGH8.7A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala be...
CVE-2024-48460MEDIUM4.3An issue in Eugeny Tabby 1.0.213 allows a remote attacker to obtain sensitive information via the server and sends the S...
CVE-2024-46450HIGH8.1Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attacke...
CVE-2024-57583CRITICAL9.8Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the for...
CVE-2024-57582CRITICAL9.8Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer fu...
CVE-2024-57581CRITICAL9.8Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCf...
CVE-2024-57580CRITICAL9.8Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName fu...
CVE-2024-57579CRITICAL9.8Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the limitSpeedUp parameter in the formSetClientSt...
CVE-2024-57578HIGH8.8Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the funcpara1 parameter in the formSetCfm functio...
CVE-2024-57577MEDIUM5.7Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan fu...
CVE-2024-57575CRITICAL9.8Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_...
CVE-2024-56515MEDIUM6.5Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. If SVG or JPEGXL thumbnai...
CVE-2024-56136MEDIUM5.3Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above ...
CVE-2024-55954HIGH8.7OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/use...
CVE-2024-52791HIGH7.5Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR makes requests to oth...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now