2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57471 | CRITICAL | 9.8 | 0.8% | Jan 14, 2025 | H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless ne... |
| CVE-2024-48760 | CRITICAL | 9.8 | 45.1% | Jan 14, 2025 | An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacke... |
| CVE-2024-49375 | CRITICAL | 9 | 0.9% | Jan 14, 2025 | Open source machine learning framework. A vulnerability has been identified in Rasa that enables an attacker who has the... |
| CVE-2024-48856 | CRITICAL | 9.8 | 0.6% | Jan 14, 2025 | Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker ... |
| CVE-2024-13181 | CRITICAL | 9.8 | 32.4% | Jan 14, 2025 | Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authenticatio... |
| CVE-2024-13179 | CRITICAL | 9.8 | 61.8% | Jan 14, 2025 | Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authenticatio... |
| CVE-2024-39761 | CRITICAL | 9.8 | 8.2% | Jan 14, 2025 | Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A... |
| CVE-2024-39760 | CRITICAL | 9.8 | 17.4% | Jan 14, 2025 | Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A... |
| CVE-2024-39759 | CRITICAL | 9.8 | 8.2% | Jan 14, 2025 | Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A... |
| CVE-2024-39754 | CRITICAL | 9.8 | 1.3% | Jan 14, 2025 | A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafte... |
| CVE-2024-39608 | CRITICAL | 9.8 | 1.4% | Jan 14, 2025 | A firmware update vulnerability exists in the login.cgi functionality of Wavlink AC3000 M33A8.V5030.210505. A specially ... |
| CVE-2024-39602 | CRITICAL | 9.1 | 2.3% | Jan 14, 2025 | An external config control vulnerability exists in the nas.cgi set_nas() functionality of Wavlink AC3000 M33A8.V5030.210... |
| CVE-2024-39280 | CRITICAL | 9.1 | 34.2% | Jan 14, 2025 | An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030... |
| CVE-2024-38666 | CRITICAL | 9.1 | 18.9% | Jan 14, 2025 | An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC300... |
| CVE-2024-36290 | CRITICAL | 9.8 | 1.4% | Jan 14, 2025 | A buffer overflow vulnerability exists in the login.cgi Goto_chidx() functionality of Wavlink AC3000 M33A8.V5030.210505.... |
| CVE-2024-36258 | CRITICAL | 9.8 | 12.4% | Jan 14, 2025 | A stack-based buffer overflow vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC... |
| CVE-2024-34166 | CRITICAL | 9.8 | 15.8% | Jan 14, 2025 | An os command injection vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M... |
| CVE-2024-55591 | CRITICAL | 9.8 | 98.3% | Jan 14, 2025 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro... |
| CVE-2024-48886 | CRITICAL | 9.8 | 0.5% | Jan 14, 2025 | A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0... |
| CVE-2024-48884 | CRITICAL | 9.1 | 14.9% | Jan 14, 2025 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager ... |
| CVE-2024-47571 | CRITICAL | 9.8 | 0.9% | Jan 14, 2025 | An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker ... |
| CVE-2024-35276 | CRITICAL | 9.8 | 0.4% | Jan 14, 2025 | A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7... |
| CVE-2024-23106 | CRITICAL | 9.8 | 0.9% | Jan 14, 2025 | An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and... |
| CVE-2024-56841 | CRITICAL | 9.1 | 0.5% | Jan 14, 2025 | A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerab... |
| CVE-2024-12919 | CRITICAL | 9.8 | 0.5% | Jan 14, 2025 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now