2024 CVE Vulnerabilities
39,220 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48733 | HIGH | 8.8 | 0.7% | Oct 30, 2024 | SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to e... |
| CVE-2024-48093 | HIGH | 8 | 0.6% | Oct 30, 2024 | Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Exe... |
| CVE-2024-48271 | HIGH | 8.8 | 0.9% | Oct 30, 2024 | D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly ... |
| CVE-2024-48647 | HIGH | 7.2 | 0.8% | Oct 30, 2024 | A file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbit... |
| CVE-2024-48646 | HIGH | 8.1 | 0.5% | Oct 30, 2024 | An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files with... |
| CVE-2024-48214 | HIGH | 8.4 | 1.0% | Oct 30, 2024 | KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local netw... |
| CVE-2024-42041 | HIGH | 8.1 | 0.3% | Oct 30, 2024 | The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 f... |
| CVE-2024-37573 | HIGH | 8.4 | 0.2% | Oct 30, 2024 | The Talkatone com.talkatone.android application 8.4.6 for Android enables any installed application (with no permissions... |
| CVE-2024-36060 | HIGH | 8.8 | 1.4% | Oct 30, 2024 | EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping ... |
| CVE-2024-51258 | HIGH | 8.8 | 0.5% | Oct 30, 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm... |
| CVE-2024-51301 | HIGH | 8.8 | 0.6% | Oct 30, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51300 | HIGH | 8.8 | 0.6% | Oct 30, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51299 | HIGH | 8.8 | 0.6% | Oct 30, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51296 | HIGH | 8.8 | 0.6% | Oct 30, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51257 | HIGH | 8.8 | 0.4% | Oct 30, 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm... |
| CVE-2024-33700 | HIGH | 7.5 | 0.8% | Oct 30, 2024 | The LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP functionalit... |
| CVE-2024-33699 | HIGH | 8.8 | 9.2% | Oct 30, 2024 | The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers t... |
| CVE-2024-33623 | HIGH | 7.5 | 11.4% | Oct 30, 2024 | A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R0.40e6. A specially ... |
| CVE-2024-31152 | HIGH | 7.5 | 17.2% | Oct 30, 2024 | The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web applicat... |
| CVE-2024-28875 | HIGH | 8.1 | 0.7% | Oct 30, 2024 | A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthoriz... |
| CVE-2024-28052 | HIGH | 7.5 | 0.7% | Oct 30, 2024 | The WBR-6012 is a wireless SOHO router. It is a low-cost device which functions as an internet gateway for homes and sma... |
| CVE-2024-24777 | HIGH | 8.8 | 7.0% | Oct 30, 2024 | A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R... |
| CVE-2024-23309 | HIGH | 8.1 | 0.9% | Oct 30, 2024 | The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due... |
| CVE-2024-51304 | HIGH | 8.8 | 0.6% | Oct 30, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-9632 | HIGH | 7.8 | 0.9% | Oct 30, 2024 | A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker ma... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now