2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39357HIGH7.2A stack-based buffer overflow vulnerability exists in the wireless.cgi SetName() functionality of Wavlink AC3000 M33A8.V...
CVE-2024-39299HIGH7.2A buffer overflow vulnerability exists in the qos.cgi qos_sta_settings() functionality of Wavlink AC3000 M33A8.V5030.210...
CVE-2024-39294HIGH7.2A buffer overflow vulnerability exists in the adm.cgi set_wzdgw4G() functionality of Wavlink AC3000 M33A8.V5030.210505. ...
CVE-2024-39288HIGH7.2A buffer overflow vulnerability exists in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030...
CVE-2024-39280CRITICAL9.1An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030...
CVE-2024-39273HIGH8.1A firmware update vulnerability exists in the fw_check.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A speciall...
CVE-2024-38666CRITICAL9.1An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC300...
CVE-2024-37357HIGH7.2A buffer overflow vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A ...
CVE-2024-37186HIGH7.2An os command injection vulnerability exists in the adm.cgi set_ledonoff() functionality of Wavlink AC3000 M33A8.V5030.2...
CVE-2024-37184HIGH7.2A buffer overflow vulnerability exists in the adm.cgi rep_as_bridge() functionality of Wavlink AC3000 M33A8.V5030.210505...
CVE-2024-36493HIGH7.2A stack-based buffer overflow vulnerability exists in the wireless.cgi set_wifi_basic() functionality of Wavlink AC3000 ...
CVE-2024-36295HIGH7.2A command execution vulnerability exists in the qos.cgi qos_sta() functionality of Wavlink AC3000 M33A8.V5030.210505. A ...
CVE-2024-36290CRITICAL9.8A buffer overflow vulnerability exists in the login.cgi Goto_chidx() functionality of Wavlink AC3000 M33A8.V5030.210505....
CVE-2024-36272HIGH7.2A buffer overflow vulnerability exists in the usbip.cgi set_info() functionality of Wavlink AC3000 M33A8.V5030.210505. A...
CVE-2024-36258CRITICAL9.8A stack-based buffer overflow vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC...
CVE-2024-34544HIGH7.2A command injection vulnerability exists in the wireless.cgi AddMac() functionality of Wavlink AC3000 M33A8.V5030.210505...
CVE-2024-34166CRITICAL9.8An os command injection vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M...
CVE-2024-21797HIGH7.2A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. ...
CVE-2024-7344HIGH8.2Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded ...
CVE-2024-56497MEDIUM6.7An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail vers...
CVE-2024-55593LOW2.7A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3...
CVE-2024-55591CRITICAL9.8An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro...
CVE-2024-54021MEDIUM5.8An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fort...
CVE-2024-52969MEDIUM6.5An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiS...
CVE-2024-52967MEDIUM4.8An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now