2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-53553CRITICAL9.1An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web reque...
CVE-2024-57583CRITICAL9.8Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the for...
CVE-2024-57582CRITICAL9.8Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer fu...
CVE-2024-57581CRITICAL9.8Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCf...
CVE-2024-57580CRITICAL9.8Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName fu...
CVE-2024-57579CRITICAL9.8Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the limitSpeedUp parameter in the formSetClientSt...
CVE-2024-57575CRITICAL9.8Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_...
CVE-2024-57684CRITICAL9.8An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated at...
CVE-2024-57768CRITICAL9.8JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRo...
CVE-2024-50563CRITICAL9.8A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, F...
CVE-2024-48885CRITICAL9.1A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder...
CVE-2024-57726CRITICAL9.9SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to creat...
CVE-2024-48126CRITICAL9.8HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service...
CVE-2024-12084CRITICAL9.8A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-cont...
CVE-2024-9636CRITICAL9.8The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3....
CVE-2024-12297CRITICAL9.2Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Althou...
CVE-2024-57766CRITICAL9.1MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table...
CVE-2024-57764CRITICAL9.1MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table...
CVE-2024-57763CRITICAL9.1MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table...
CVE-2024-57483CRITICAL9.8Tenda i24 V2.0.0.5 is vulnerable to Buffer Overflow in the addWifiMacFilter function.
CVE-2024-57473CRITICAL9.8H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address edit...
CVE-2024-54142CRITICAL9Discourse AI is a Discourse plugin which provides a number of AI features. When sharing Discourse AI Bot conversations i...
CVE-2024-57482CRITICAL9.8H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 5G wireless netw...
CVE-2024-57480CRITICAL9.8H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration...
CVE-2024-57479CRITICAL9.8H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address upda...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now