2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-24333CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc paramet...
CVE-2024-24332CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url paramete...
CVE-2024-24331CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param...
CVE-2024-24330CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enab...
CVE-2024-24329CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param...
CVE-2024-24328CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param...
CVE-2024-24327CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass pa...
CVE-2024-24326CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable pa...
CVE-2024-24325CRITICAL9.8TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable param...
CVE-2024-24324CRITICAL9.8TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root stored in /etc/shadow.
CVE-2024-1034CRITICAL9.8A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadFile...
CVE-2024-1032CRITICAL9.8A vulnerability classified as critical was found in openBI up to 1.0.8. Affected by this vulnerability is the function t...
CVE-2024-1061CRITICAL9.8The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerabilit...
CVE-2024-21488CRITICAL9.8Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_proce...
CVE-2024-1027CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Facebook News Feed Like 1.0. Affected is ...
CVE-2024-1021CRITICAL9.8A vulnerability, which was classified as critical, has been found in Rebuild up to 3.5.5. Affected by this issue is the ...
CVE-2024-24141CRITICAL9.8Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter.
CVE-2024-1009CRITICAL9.8A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by t...
CVE-2024-23827CRITICAL9.8Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into t...
CVE-2024-23822CRITICAL9.8Thruk is a multibackend monitoring webinterface. Prior to 3.12, the Thruk web monitoring application presents a vulnera...
CVE-2024-1015CRITICAL9.8Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacke...
CVE-2024-1001CRITICAL9.8A vulnerability classified as critical has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected is the function...
CVE-2024-23790CRITICAL9.8Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to ...
CVE-2024-0996CRITICAL9.8A vulnerability classified as critical has been found in Tenda i9 1.0.0.9(4122). This affects the function formSetCfm of...
CVE-2024-0995CRITICAL9.8A vulnerability was found in Tenda W6 1.0.0.9(4122). It has been rated as critical. Affected by this issue is the functi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now