2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-33298MEDIUM6.1Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code v...
CVE-2024-33297MEDIUM4.7Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the camp...
CVE-2024-12847CRITICAL9.8NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated a...
CVE-2024-54910MEDIUM4.7Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.
CVE-2024-6880MEDIUM6.9During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping ...
CVE-2024-6662HIGH8.7Websites managed by MegaBIP in versions below 5.15 are vulnerable to Cross-Site Request Forgery (CSRF) as the form avail...
CVE-2024-57228HIGH8Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_...
CVE-2024-57227HIGH8Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc...
CVE-2024-57226HIGH8Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_...
CVE-2024-57225CRITICAL9.8Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the re...
CVE-2024-57224CRITICAL9.8Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc...
CVE-2024-57223CRITICAL9.8Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc...
CVE-2024-57222MEDIUM6.3Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc...
CVE-2024-54687MEDIUM6.1Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndS...
CVE-2024-57214MEDIUM6.3TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parame...
CVE-2024-57213MEDIUM6.3TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd para...
CVE-2024-57212MEDIUM5.1TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode paramet...
CVE-2024-57211HIGH8TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne para...
CVE-2024-54849MEDIUM5.9An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitiv...
CVE-2024-54848HIGH7.4Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communica...
CVE-2024-54847MEDIUM5.9An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH) parameters and access ...
CVE-2024-54846MEDIUM5.9An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and access sensitive data o...
CVE-2024-56511CRITICAL9.8DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in t...
CVE-2024-50807MEDIUM6.1Trippo Responsive Filemanager 9.14.0 is vulnerable to Cross Site Scripting (XSS) via file upload using the svg and pdf e...
CVE-2024-46210HIGH7.2An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitra...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now