2024 CVE Vulnerabilities

39,224 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9134HIGH8.3Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application acce...
CVE-2024-9133MEDIUM5.6A user with administrator privileges is able to retrieve authentication tokens
CVE-2024-9132CRITICAL9.8The administrator is able to configure an insecure captive portal script
CVE-2024-9131HIGH7.2A user with administrator privileges can perform command injection
CVE-2024-7142MEDIUM4.6On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA...
CVE-2024-47520HIGH7.6A user with advanced report application access rights can perform actions for which they are not authorized
CVE-2024-47519HIGH7.1Backup uploads to ETM subject to man-in-the-middle interception
CVE-2024-47518HIGH7.6Specially constructed queries targeting ETM could discover active remote access sessions
CVE-2024-47517MEDIUM6.8Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
CVE-2024-7095MEDIUM4.3On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under s...
CVE-2024-5872MEDIUM6.5On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, whi...
CVE-2024-54998MEDIUM5.4MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter ...
CVE-2024-54997MEDIUM5.4MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field ...
CVE-2024-54996HIGH8.8MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and...
CVE-2024-54994MEDIUM6.5MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_nam...
CVE-2024-6437MEDIUM5.8On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next ...
CVE-2024-33299MEDIUM4.7Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the Firs...
CVE-2024-33298MEDIUM6.1Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code v...
CVE-2024-33297MEDIUM4.7Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the camp...
CVE-2024-12847CRITICAL9.8NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated a...
CVE-2024-54910MEDIUM4.7Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.
CVE-2024-6880MEDIUM6.9During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping ...
CVE-2024-6662HIGH8.7Websites managed by MegaBIP in versions below 5.15 are vulnerable to Cross-Site Request Forgery (CSRF) as the form avail...
CVE-2024-57228HIGH8Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_...
CVE-2024-57227HIGH8Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now