2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57018 | HIGH | 8.8 | 1.6% | Jan 15, 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" p... |
| CVE-2024-57017 | HIGH | 8.8 | 1.6% | Jan 15, 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" p... |
| CVE-2024-57016 | HIGH | 8.8 | 1.6% | Jan 15, 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" p... |
| CVE-2024-57015 | HIGH | 8.8 | 1.6% | Jan 15, 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" p... |
| CVE-2024-57014 | HIGH | 8.8 | 1.2% | Jan 15, 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour... |
| CVE-2024-57013 | HIGH | 8.8 | 1.6% | Jan 15, 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch"... |
| CVE-2024-57012 | HIGH | 8.8 | 1.6% | Jan 15, 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" p... |
| CVE-2024-57011 | HIGH | 8.8 | 1.7% | Jan 15, 2025 | TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute"... |
| CVE-2024-52783 | MEDIUM | 5.1 | 0.2% | Jan 15, 2025 | Insecure permissions in the XNetSocketClient component of XINJE XDPPro.exe v3.2.2 to v3.7.17c allows attackers to execut... |
| CVE-2024-50954 | HIGH | 7.5 | 0.4% | Jan 15, 2025 | The XINJE XL5E-16T and XD5E-24R-E programmable logic controllers V3.5.3b-V3.7.2a have a vulnerability in handling Modbus... |
| CVE-2024-50953 | HIGH | 7.5 | 0.4% | Jan 15, 2025 | An issue in XINJE XL5E-16T V3.7.2a allows attackers to cause a Denial of Service (DoS) via a crafted Modbus message. |
| CVE-2024-8603 | HIGH | 8.2 | 0.3% | Jan 15, 2025 | A “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runti... |
| CVE-2024-56295 | MEDIUM | 6.5 | 0.4% | Jan 15, 2025 | Missing Authorization vulnerability in Ays Pro Poll Maker poll-maker allows Exploiting Incorrectly Configured Access Con... |
| CVE-2024-47140 | MEDIUM | 5.4 | 0.7% | Jan 15, 2025 | A cross-site scripting (xss) vulnerability exists in the add_alert_check page of Observium CE 24.4.13528. A specially cr... |
| CVE-2024-47002 | MEDIUM | 5.4 | 14.4% | Jan 15, 2025 | A html code injection vulnerability exists in the vlan management part of Observium CE 24.4.13528. A specially crafted H... |
| CVE-2024-45061 | MEDIUM | 5.4 | 1.1% | Jan 15, 2025 | A cross-site scripting (xss) vulnerability exists in the weather map editor functionality of Observium CE 24.4.13528. A ... |
| CVE-2024-12084 | CRITICAL | 9.8 | 72.1% | Jan 15, 2025 | A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-cont... |
| CVE-2024-11322 | HIGH | 7.5 | 0.6% | Jan 15, 2025 | A denial-of-service vulnerability exists in CyberPower PowerPanel Business (PPB) 4.11.0. An unauthenticated remote atta... |
| CVE-2024-5198 | LOW | 3.3 | 0.1% | Jan 15, 2025 | OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with inval... |
| CVE-2024-57903 | MEDIUM | 5.5 | 0.2% | Jan 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: restrict SO_REUSEPORT to inet sockets After b... |
| CVE-2024-57902 | MEDIUM | 5.5 | 0.3% | Jan 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: af_packet: fix vlan_get_tci() vs MSG_PEEK Blamed c... |
| CVE-2024-57901 | MEDIUM | 5.5 | 0.3% | Jan 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: af_packet: fix vlan_get_protocol_dgram() vs MSG_PEE... |
| CVE-2024-57900 | HIGH | 7.8 | 0.3% | Jan 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: ila: serialize calls to nf_register_net_hooks() sy... |
| CVE-2024-57899 | HIGH | 7.8 | 0.2% | Jan 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix mbss changed flags corruption o... |
| CVE-2024-57898 | LOW | 3.3 | 0.2% | Jan 15, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: clear link ID from bitmap during li... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now