2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-51254HIGH8.8DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm...
CVE-2024-49685HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Custom Twitter Feeds (Tweets Widget) custom-twitter-feeds...
CVE-2024-43984HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue af...
CVE-2024-43383HIGH8.1Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's...
CVE-2024-21537HIGH8.9Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the inse...
CVE-2024-48311HIGH8.8Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function.
CVE-2024-10559HIGH7.8A vulnerability was found in SourceCodester Airport Booking Management System 1.0 and classified as critical. Affected b...
CVE-2024-51426HIGH8.8An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an...
CVE-2024-51425HIGH8.8An issue in the WaterToken smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have ...
CVE-2024-51243HIGH7.2The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deploy...
CVE-2024-48735HIGH7.7Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote ...
CVE-2024-48734HIGH8.8Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote atta...
CVE-2024-48733HIGH8.8SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to e...
CVE-2024-48093HIGH8Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Exe...
CVE-2024-48271HIGH8.8D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly ...
CVE-2024-48647HIGH7.2A file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbit...
CVE-2024-48646HIGH8.1An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files with...
CVE-2024-48214HIGH8.4KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local netw...
CVE-2024-42041HIGH8.1The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 f...
CVE-2024-37573HIGH8.4The Talkatone com.talkatone.android application 8.4.6 for Android enables any installed application (with no permissions...
CVE-2024-36060HIGH8.8EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping ...
CVE-2024-51258HIGH8.8DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm...
CVE-2024-51301HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51300HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51299HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now