2024 CVE Vulnerabilities
39,224 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57226 | HIGH | 8 | 1.2% | Jan 10, 2025 | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_... |
| CVE-2024-57225 | CRITICAL | 9.8 | 1.6% | Jan 10, 2025 | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the re... |
| CVE-2024-57224 | CRITICAL | 9.8 | 1.6% | Jan 10, 2025 | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc... |
| CVE-2024-57223 | CRITICAL | 9.8 | 1.6% | Jan 10, 2025 | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc... |
| CVE-2024-57222 | MEDIUM | 6.3 | 0.8% | Jan 10, 2025 | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc... |
| CVE-2024-54687 | MEDIUM | 6.1 | 0.3% | Jan 10, 2025 | Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndS... |
| CVE-2024-57214 | MEDIUM | 6.3 | 0.7% | Jan 10, 2025 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parame... |
| CVE-2024-57213 | MEDIUM | 6.3 | 0.7% | Jan 10, 2025 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd para... |
| CVE-2024-57212 | MEDIUM | 5.1 | 0.7% | Jan 10, 2025 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode paramet... |
| CVE-2024-57211 | HIGH | 8 | 1.2% | Jan 10, 2025 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne para... |
| CVE-2024-54849 | MEDIUM | 5.9 | 0.4% | Jan 10, 2025 | An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitiv... |
| CVE-2024-54848 | HIGH | 7.4 | 0.3% | Jan 10, 2025 | Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communica... |
| CVE-2024-54847 | MEDIUM | 5.9 | 0.4% | Jan 10, 2025 | An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH) parameters and access ... |
| CVE-2024-54846 | MEDIUM | 5.9 | 0.4% | Jan 10, 2025 | An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and access sensitive data o... |
| CVE-2024-56511 | CRITICAL | 9.8 | 20.9% | Jan 10, 2025 | DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in t... |
| CVE-2024-50807 | MEDIUM | 6.1 | 0.3% | Jan 10, 2025 | Trippo Responsive Filemanager 9.14.0 is vulnerable to Cross Site Scripting (XSS) via file upload using the svg and pdf e... |
| CVE-2024-46210 | HIGH | 7.2 | 0.6% | Jan 10, 2025 | An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitra... |
| CVE-2024-29971 | CRITICAL | 9.8 | 0.4% | Jan 10, 2025 | Scontain SCONE 5.8.0 has an interface vulnerability that leads to state corruption via injected signals. |
| CVE-2024-29970 | CRITICAL | 9.8 | 0.4% | Jan 10, 2025 | Fortanix Enclave OS 3.36.1941-EM has an interface vulnerability that leads to state corruption via injected signals. |
| CVE-2024-25371 | HIGH | 7.5 | 0.4% | Jan 10, 2025 | Gramine before a390e33e16ed374a40de2344562a937f289be2e1 suffers from an Interface vulnerability due to mismatching SW si... |
| CVE-2024-57687 | CRITICAL | 9.8 | 2.6% | Jan 10, 2025 | An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v... |
| CVE-2024-57686 | CRITICAL | 9.8 | 1.6% | Jan 10, 2025 | A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record Sys... |
| CVE-2024-41787 | HIGH | 8.1 | 1.1% | Jan 10, 2025 | IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 could allow a remote attacker to bypass security rest... |
| CVE-2024-57823 | MEDIUM | 5.5 | 0.3% | Jan 10, 2025 | In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser... |
| CVE-2024-57822 | MEDIUM | 5.5 | 0.3% | Jan 10, 2025 | In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now