2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-45754HIGH7.2An issue was discovered in the centreon-bi-server component in Centreon BI Server 24.04.x before 24.04.3, 23.10.x before...
CVE-2024-35522HIGH7.2Netgear EX3700 ' AC750 WiFi Range Extender Essentials Edition before 1.0.0.98 contains an authenticated command injectio...
CVE-2024-35517HIGH7.2Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.
CVE-2024-48938HIGH7.5Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails...
CVE-2024-48788HIGH7.5An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firm...
CVE-2024-46468HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker...
CVE-2024-48777HIGH7.5LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware upda...
CVE-2024-48776HIGH7.5An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware updat...
CVE-2024-48775HIGH7.5An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the ...
CVE-2024-48774HIGH7.5An issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information vi...
CVE-2024-48773HIGH7.5An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update process
CVE-2024-48771HIGH7.5An issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive informat...
CVE-2024-48770HIGH8.2An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via t...
CVE-2024-48768HIGH7.5An issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to obtain sensitive inform...
CVE-2024-38365HIGH8.1btcd is an alternative full node bitcoin implementation written in Go (golang). The btcd Bitcoin client (versions 0.10 t...
CVE-2024-8912HIGH7.5An HTTP Request Smuggling vulnerability in Looker allowed an unauthorized attacker to capture HTTP responses destined fo...
CVE-2024-48020HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx Backup and...
CVE-2024-9859HIGH8.8Type confusion in WebAssembly in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to execute arbitrary co...
CVE-2024-47877HIGH7.5Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow ...
CVE-2024-44734HIGH7.5Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a...
CVE-2024-44414HIGH8.8A vulnerability was discovered in FBM_292W-21.03.10V, which has been classified as critical. This issue affects the sub_...
CVE-2024-44413HIGH8.8A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgr...
CVE-2024-42018HIGH7.7An issue was discovered in Atos Eviden SMC xScale before 1.6.6. During initialization of nodes, some configuration param...
CVE-2024-9046HIGH7.8A DLL hijack vulnerability was reported in Lenovo stARstudio that could allow a local attacker to execute code with elev...
CVE-2024-8376HIGH7.5In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now