2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0883 | CRITICAL | 9.8 | 0.6% | Jan 25, 2024 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critic... |
| CVE-2024-22529 | CRITICAL | 9.8 | 1.7% | Jan 25, 2024 | TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of fo... |
| CVE-2024-22729 | CRITICAL | 9.8 | 70.8% | Jan 25, 2024 | NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter ... |
| CVE-2024-22751 | CRITICAL | 9.8 | 1.2% | Jan 24, 2024 | D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function. |
| CVE-2024-23897 | CRITICAL | 9.8 | 100.0% | Jan 24, 2024 | Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an... |
| CVE-2024-22651 | CRITICAL | 9.8 | 20.2% | Jan 24, 2024 | There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmwa... |
| CVE-2024-22309 | CRITICAL | 9.8 | 0.5% | Jan 24, 2024 | Deserialization of Untrusted Data vulnerability in QuantumCloud ChatBot with AI.This issue affects ChatBot with AI: from... |
| CVE-2024-22284 | CRITICAL | 9.8 | 0.6% | Jan 24, 2024 | Deserialization of Untrusted Data vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/... |
| CVE-2024-0808 | CRITICAL | 9.8 | 0.5% | Jan 24, 2024 | Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap... |
| CVE-2024-23636 | CRITICAL | 9.8 | 0.8% | Jan 23, 2024 | SOFARPC is a Java RPC framework. SOFARPC defaults to using the SOFA Hessian protocol to deserialize received data, while... |
| CVE-2024-22205 | CRITICAL | 9.8 | 1.0% | Jan 23, 2024 | Whoogle Search is a self-hosted metasearch engine. In versions 0.8.3 and prior, the `window` endpoint does not sanitize ... |
| CVE-2024-22203 | CRITICAL | 9.8 | 1.0% | Jan 23, 2024 | Whoogle Search is a self-hosted metasearch engine. In versions prior to 0.8.4, the `element` method in `app/routes.py` d... |
| CVE-2024-22663 | CRITICAL | 9.8 | 1.7% | Jan 23, 2024 | TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg |
| CVE-2024-22662 | CRITICAL | 9.8 | 0.9% | Jan 23, 2024 | TOTOLINK A3700R_V9.1.2u.6165_20211012 has a stack overflow vulnerability via setParentalRules |
| CVE-2024-22660 | CRITICAL | 9.8 | 0.9% | Jan 23, 2024 | TOTOLINK_A3700R_V9.1.2u.6165_20211012has a stack overflow vulnerability via setLanguageCfg |
| CVE-2024-22076 | CRITICAL | 9.8 | 1.1% | Jan 23, 2024 | MyQ Print Server before 8.2 patch 43 allows remote authenticated administrators to execute arbitrary code via PHP script... |
| CVE-2024-0784 | CRITICAL | 9.8 | 0.7% | Jan 22, 2024 | A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function ... |
| CVE-2024-0783 | CRITICAL | 9.8 | 1.2% | Jan 22, 2024 | A vulnerability was found in Project Worlds Online Admission System 1.0 and classified as critical. This issue affects s... |
| CVE-2024-0204 | CRITICAL | 9.8 | 95.1% | Jan 22, 2024 | Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via ... |
| CVE-2024-0778 | CRITICAL | 9.8 | 32.1% | Jan 22, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in Uniview ISC 2500-S ... |
| CVE-2024-23771 | CRITICAL | 9.8 | 1.1% | Jan 22, 2024 | darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remot... |
| CVE-2024-23752 | CRITICAL | 9.8 | 1.0% | Jan 22, 2024 | GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the ge... |
| CVE-2024-23751 | CRITICAL | 9.8 | 0.7% | Jan 22, 2024 | LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, S... |
| CVE-2024-23731 | CRITICAL | 9.8 | 1.1% | Jan 21, 2024 | The OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yam... |
| CVE-2024-23730 | CRITICAL | 9.8 | 1.2% | Jan 21, 2024 | The OpenAPI and ChatGPT plugin loaders in LlamaHub (aka llama-hub) before 0.0.67 allow attackers to execute arbitrary co... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now