2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-9054HIGH8.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Inform...
CVE-2024-43684HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-...
CVE-2024-46078HIGH7.5itsourcecode Sports Management System Project 1.0 is vulnerable to SQL Injection in the function delete_category of the ...
CVE-2024-41512HIGH8.8A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attacker...
CVE-2024-38040HIGH7.5There is a local file inclusion vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthen...
CVE-2024-46486HIGH8TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv fu...
CVE-2024-47769HIGH7.5IDURAR is open source ERP CRM accounting invoicing software. The vulnerability exists in the corePublicRouter.js file. U...
CVE-2024-47768HIGH8.1Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to ...
CVE-2024-47183HIGH8.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Ser...
CVE-2024-9515HIGH8.8A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been classified as critical. This affects the function...
CVE-2024-9514HIGH8.8A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been declared as critical. This vulnerability affects ...
CVE-2024-47790HIGH8.7** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of insecure Real-...
CVE-2024-47789HIGH8.7** UNSUPPORTED WHEN ASSIGNED ** This vulnerability exists in D3D Security IP Camera D8801 due to usage of weak authentic...
CVE-2024-47655HIGH8.8This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than t...
CVE-2024-47654HIGH7.5This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP request...
CVE-2024-47652HIGH8.1This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the...
CVE-2024-6400HIGH7.5Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finr...
CVE-2024-47850HIGH7.5CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a sing...
CVE-2024-42417HIGH8.8Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker...
CVE-2024-46658HIGH8Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.
CVE-2024-41596HIGH8Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because o...
CVE-2024-41595HIGH8DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cg...
CVE-2024-41594HIGH7.5An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the http...
CVE-2024-41592HIGH8DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because Ge...
CVE-2024-41590HIGH8Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now