2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-57018HIGH8.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" p...
CVE-2024-57017HIGH8.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" p...
CVE-2024-57016HIGH8.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" p...
CVE-2024-57015HIGH8.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" p...
CVE-2024-57014HIGH8.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour...
CVE-2024-57013HIGH8.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch"...
CVE-2024-57012HIGH8.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" p...
CVE-2024-57011HIGH8.8TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute"...
CVE-2024-52783MEDIUM5.1Insecure permissions in the XNetSocketClient component of XINJE XDPPro.exe v3.2.2 to v3.7.17c allows attackers to execut...
CVE-2024-50954HIGH7.5The XINJE XL5E-16T and XD5E-24R-E programmable logic controllers V3.5.3b-V3.7.2a have a vulnerability in handling Modbus...
CVE-2024-50953HIGH7.5An issue in XINJE XL5E-16T V3.7.2a allows attackers to cause a Denial of Service (DoS) via a crafted Modbus message.
CVE-2024-8603HIGH8.2A “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runti...
CVE-2024-56295MEDIUM6.5Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Con...
CVE-2024-47140MEDIUM5.4A cross-site scripting (xss) vulnerability exists in the add_alert_check page of Observium CE 24.4.13528. A specially cr...
CVE-2024-47002MEDIUM5.4A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528. A specially crafted H...
CVE-2024-45061MEDIUM5.4A cross-site scripting (xss) vulnerability exists in the weather map editor functionality of Observium CE 24.4.13528. A ...
CVE-2024-12084CRITICAL9.8A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-cont...
CVE-2024-11322HIGH7.5A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0. An unauthenticated remote atta...
CVE-2024-5198LOW3.3OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with inval...
CVE-2024-57903MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: restrict SO_REUSEPORT to inet sockets After b...
CVE-2024-57902MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: af_packet: fix vlan_get_tci() vs MSG_PEEK Blamed c...
CVE-2024-57901MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: af_packet: fix vlan_get_protocol_dgram() vs MSG_PEE...
CVE-2024-57900HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ila: serialize calls to nf_register_net_hooks() sy...
CVE-2024-57899HIGH7.8In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix mbss changed flags corruption o...
CVE-2024-57898LOW3.3In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: clear link ID from bitmap during li...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now