2024 CVE Vulnerabilities

39,220 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-48733HIGH8.8SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to e...
CVE-2024-48093HIGH8Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Exe...
CVE-2024-48271HIGH8.8D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly ...
CVE-2024-48647HIGH7.2A file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbit...
CVE-2024-48646HIGH8.1An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files with...
CVE-2024-48214HIGH8.4KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local netw...
CVE-2024-42041HIGH8.1The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 f...
CVE-2024-37573HIGH8.4The Talkatone com.talkatone.android application 8.4.6 for Android enables any installed application (with no permissions...
CVE-2024-36060HIGH8.8EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping ...
CVE-2024-51258HIGH8.8DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm...
CVE-2024-51301HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51300HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51299HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51296HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51257HIGH8.8DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm...
CVE-2024-33700HIGH7.5The LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP functionalit...
CVE-2024-33699HIGH8.8The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers t...
CVE-2024-33623HIGH7.5A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R0.40e6. A specially ...
CVE-2024-31152HIGH7.5The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web applicat...
CVE-2024-28875HIGH8.1A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthoriz...
CVE-2024-28052HIGH7.5The WBR-6012 is a wireless SOHO router. It is a low-cost device which functions as an internet gateway for homes and sma...
CVE-2024-24777HIGH8.8A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R...
CVE-2024-23309HIGH8.1The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due...
CVE-2024-51304HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-9632HIGH7.8A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker ma...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now