2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-53553 | CRITICAL | 9.1 | 0.5% | Jan 16, 2025 | An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web reque... |
| CVE-2024-57583 | CRITICAL | 9.8 | 1.5% | Jan 16, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the for... |
| CVE-2024-57582 | CRITICAL | 9.8 | 0.7% | Jan 16, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer fu... |
| CVE-2024-57581 | CRITICAL | 9.8 | 0.7% | Jan 16, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCf... |
| CVE-2024-57580 | CRITICAL | 9.8 | 0.7% | Jan 16, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName fu... |
| CVE-2024-57579 | CRITICAL | 9.8 | 0.7% | Jan 16, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the limitSpeedUp parameter in the formSetClientSt... |
| CVE-2024-57575 | CRITICAL | 9.8 | 0.8% | Jan 16, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_... |
| CVE-2024-57684 | CRITICAL | 9.8 | 14.4% | Jan 16, 2025 | An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated at... |
| CVE-2024-57768 | CRITICAL | 9.8 | 0.5% | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRo... |
| CVE-2024-50563 | CRITICAL | 9.8 | 0.6% | Jan 16, 2025 | A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, F... |
| CVE-2024-48885 | CRITICAL | 9.1 | 0.8% | Jan 16, 2025 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder... |
| CVE-2024-57726 | CRITICAL | 9.9 | 9.3% | Jan 15, 2025 | SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to creat... |
| CVE-2024-48126 | CRITICAL | 9.8 | 0.4% | Jan 15, 2025 | HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to vendor support and service... |
| CVE-2024-12084 | CRITICAL | 9.8 | 72.1% | Jan 15, 2025 | A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-cont... |
| CVE-2024-9636 | CRITICAL | 9.8 | 0.8% | Jan 15, 2025 | The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3.... |
| CVE-2024-12297 | CRITICAL | 9.2 | 0.8% | Jan 15, 2025 | Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Althou... |
| CVE-2024-57766 | CRITICAL | 9.1 | 0.5% | Jan 15, 2025 | MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table... |
| CVE-2024-57764 | CRITICAL | 9.1 | 0.5% | Jan 15, 2025 | MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table... |
| CVE-2024-57763 | CRITICAL | 9.1 | 0.5% | Jan 15, 2025 | MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table... |
| CVE-2024-57483 | CRITICAL | 9.8 | 0.6% | Jan 14, 2025 | Tenda i24 V2.0.0.5 is vulnerable to Buffer Overflow in the addWifiMacFilter function. |
| CVE-2024-57473 | CRITICAL | 9.8 | 0.8% | Jan 14, 2025 | H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address edit... |
| CVE-2024-54142 | CRITICAL | 9 | 0.4% | Jan 14, 2025 | Discourse AI is a Discourse plugin which provides a number of AI features. When sharing Discourse AI Bot conversations i... |
| CVE-2024-57482 | CRITICAL | 9.8 | 0.8% | Jan 14, 2025 | H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 5G wireless netw... |
| CVE-2024-57480 | CRITICAL | 9.8 | 0.8% | Jan 14, 2025 | H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the AP configuration... |
| CVE-2024-57479 | CRITICAL | 9.8 | 0.6% | Jan 14, 2025 | H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the mac address upda... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now