2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-47654 | HIGH | 7.5 | 0.5% | Oct 4, 2024 | This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP request... |
| CVE-2024-47652 | HIGH | 8.1 | 0.4% | Oct 4, 2024 | This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the... |
| CVE-2024-6400 | HIGH | 7.5 | 0.6% | Oct 4, 2024 | Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finr... |
| CVE-2024-47850 | HIGH | 7.5 | 0.9% | Oct 4, 2024 | CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a sing... |
| CVE-2024-42417 | HIGH | 8.8 | 6.6% | Oct 3, 2024 | Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker... |
| CVE-2024-46658 | HIGH | 8 | 23.1% | Oct 3, 2024 | Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability. |
| CVE-2024-41596 | HIGH | 8 | 0.3% | Oct 3, 2024 | Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because o... |
| CVE-2024-41595 | HIGH | 8 | 0.3% | Oct 3, 2024 | DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cg... |
| CVE-2024-41594 | HIGH | 7.5 | 0.3% | Oct 3, 2024 | An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the http... |
| CVE-2024-41592 | HIGH | 8 | 1.4% | Oct 3, 2024 | DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because Ge... |
| CVE-2024-41590 | HIGH | 8 | 0.3% | Oct 3, 2024 | Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on ... |
| CVE-2024-41589 | HIGH | 8.8 | 0.3% | Oct 3, 2024 | DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests. |
| CVE-2024-41588 | HIGH | 8 | 0.3% | Oct 3, 2024 | The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflo... |
| CVE-2024-41586 | HIGH | 8 | 0.5% | Oct 3, 2024 | A stack-based Buffer Overflow vulnerability in DrayTek Vigor310 devices through 4.3.2.6 allows a remote attacker to exec... |
| CVE-2024-41987 | HIGH | 8.6 | 0.2% | Oct 3, 2024 | The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests... |
| CVE-2024-42415 | HIGH | 7.8 | 0.5% | Oct 3, 2024 | An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Pro... |
| CVE-2024-41922 | HIGH | 7.5 | 8.0% | Oct 3, 2024 | A directory traversal vulnerability exists in the log files download functionality of Veertu Anka Build 1.42.0. A specia... |
| CVE-2024-41163 | HIGH | 7.5 | 47.1% | Oct 3, 2024 | A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. A specially crafted... |
| CVE-2024-39755 | HIGH | 7.8 | 0.4% | Oct 3, 2024 | A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially cr... |
| CVE-2024-36474 | HIGH | 7.8 | 0.4% | Oct 3, 2024 | An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Struc... |
| CVE-2024-25590 | HIGH | 7.5 | 0.7% | Oct 3, 2024 | An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for... |
| CVE-2024-5803 | HIGH | 7.5 | 0.1% | Oct 3, 2024 | The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via a... |
| CVE-2024-47614 | HIGH | 7.5 | 0.6% | Oct 3, 2024 | async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of ... |
| CVE-2024-9313 | HIGH | 8.8 | 0.6% | Oct 3, 2024 | Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same b... |
| CVE-2024-8352 | HIGH | 7.5 | 0.9% | Oct 3, 2024 | The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directory... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now