2024 CVE Vulnerabilities
39,224 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-9134 | HIGH | 8.3 | 0.6% | Jan 10, 2025 | Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application acce... |
| CVE-2024-9133 | MEDIUM | 5.6 | 0.2% | Jan 10, 2025 | A user with administrator privileges is able to retrieve authentication tokens |
| CVE-2024-9132 | CRITICAL | 9.8 | 0.7% | Jan 10, 2025 | The administrator is able to configure an insecure captive portal script |
| CVE-2024-9131 | HIGH | 7.2 | 1.4% | Jan 10, 2025 | A user with administrator privileges can perform command injection |
| CVE-2024-7142 | MEDIUM | 4.6 | 0.1% | Jan 10, 2025 | On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA... |
| CVE-2024-47520 | HIGH | 7.6 | 0.4% | Jan 10, 2025 | A user with advanced report application access rights can perform actions for which they are not authorized |
| CVE-2024-47519 | HIGH | 7.1 | 0.3% | Jan 10, 2025 | Backup uploads to ETM subject to man-in-the-middle interception |
| CVE-2024-47518 | HIGH | 7.6 | 0.4% | Jan 10, 2025 | Specially constructed queries targeting ETM could discover active remote access sessions |
| CVE-2024-47517 | MEDIUM | 6.8 | 0.4% | Jan 10, 2025 | Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access |
| CVE-2024-7095 | MEDIUM | 4.3 | 0.5% | Jan 10, 2025 | On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under s... |
| CVE-2024-5872 | MEDIUM | 6.5 | 0.3% | Jan 10, 2025 | On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, whi... |
| CVE-2024-54998 | MEDIUM | 5.4 | 0.4% | Jan 10, 2025 | MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter ... |
| CVE-2024-54997 | MEDIUM | 5.4 | 0.3% | Jan 10, 2025 | MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field ... |
| CVE-2024-54996 | HIGH | 8.8 | 0.8% | Jan 10, 2025 | MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and... |
| CVE-2024-54994 | MEDIUM | 6.5 | 0.3% | Jan 10, 2025 | MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_nam... |
| CVE-2024-6437 | MEDIUM | 5.8 | 0.5% | Jan 10, 2025 | On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next ... |
| CVE-2024-33299 | MEDIUM | 4.7 | 1.1% | Jan 10, 2025 | Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the Firs... |
| CVE-2024-33298 | MEDIUM | 6.1 | 0.8% | Jan 10, 2025 | Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code v... |
| CVE-2024-33297 | MEDIUM | 4.7 | 1.1% | Jan 10, 2025 | Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the camp... |
| CVE-2024-12847 | CRITICAL | 9.8 | 29.0% | Jan 10, 2025 | NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated a... |
| CVE-2024-54910 | MEDIUM | 4.7 | 0.4% | Jan 10, 2025 | Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function. |
| CVE-2024-6880 | MEDIUM | 6.9 | 0.5% | Jan 10, 2025 | During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping ... |
| CVE-2024-6662 | HIGH | 8.7 | 0.3% | Jan 10, 2025 | Websites managed by MegaBIP in versions below 5.15 are vulnerable to Cross-Site Request Forgery (CSRF) as the form avail... |
| CVE-2024-57228 | HIGH | 8 | 1.2% | Jan 10, 2025 | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_... |
| CVE-2024-57227 | HIGH | 8 | 1.2% | Jan 10, 2025 | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now