2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-57471CRITICAL9.8H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless ne...
CVE-2024-48760CRITICAL9.8An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacke...
CVE-2024-49375CRITICAL9Open source machine learning framework. A vulnerability has been identified in Rasa that enables an attacker who has the...
CVE-2024-48856CRITICAL9.8Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker ...
CVE-2024-13181CRITICAL9.8Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authenticatio...
CVE-2024-13179CRITICAL9.8Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authenticatio...
CVE-2024-39761CRITICAL9.8Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A...
CVE-2024-39760CRITICAL9.8Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A...
CVE-2024-39759CRITICAL9.8Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A...
CVE-2024-39754CRITICAL9.8A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafte...
CVE-2024-39608CRITICAL9.8A firmware update vulnerability exists in the login.cgi functionality of Wavlink AC3000 M33A8.V5030.210505. A specially ...
CVE-2024-39602CRITICAL9.1An external config control vulnerability exists in the nas.cgi set_nas() functionality of Wavlink AC3000 M33A8.V5030.210...
CVE-2024-39280CRITICAL9.1An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030...
CVE-2024-38666CRITICAL9.1An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC300...
CVE-2024-36290CRITICAL9.8A buffer overflow vulnerability exists in the login.cgi Goto_chidx() functionality of Wavlink AC3000 M33A8.V5030.210505....
CVE-2024-36258CRITICAL9.8A stack-based buffer overflow vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC...
CVE-2024-34166CRITICAL9.8An os command injection vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M...
CVE-2024-55591CRITICAL9.8An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro...
CVE-2024-48886CRITICAL9.8A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0...
CVE-2024-48884CRITICAL9.1A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager ...
CVE-2024-47571CRITICAL9.8An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker ...
CVE-2024-35276CRITICAL9.8A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7...
CVE-2024-23106CRITICAL9.8An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and...
CVE-2024-56841CRITICAL9.1A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerab...
CVE-2024-12919CRITICAL9.8The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now