2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41589 | HIGH | 8.8 | 0.3% | Oct 3, 2024 | DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests. |
| CVE-2024-41588 | HIGH | 8 | 0.3% | Oct 3, 2024 | The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflo... |
| CVE-2024-41586 | HIGH | 8 | 0.5% | Oct 3, 2024 | A stack-based Buffer Overflow vulnerability in DrayTek Vigor310 devices through 4.3.2.6 allows a remote attacker to exec... |
| CVE-2024-41987 | HIGH | 8.6 | 0.2% | Oct 3, 2024 | The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests... |
| CVE-2024-42415 | HIGH | 7.8 | 0.5% | Oct 3, 2024 | An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Pro... |
| CVE-2024-41922 | HIGH | 7.5 | 8.0% | Oct 3, 2024 | A directory traversal vulnerability exists in the log files download functionality of Veertu Anka Build 1.42.0. A specia... |
| CVE-2024-41163 | HIGH | 7.5 | 47.1% | Oct 3, 2024 | A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. A specially crafted... |
| CVE-2024-39755 | HIGH | 7.8 | 0.4% | Oct 3, 2024 | A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially cr... |
| CVE-2024-36474 | HIGH | 7.8 | 0.4% | Oct 3, 2024 | An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Struc... |
| CVE-2024-25590 | HIGH | 7.5 | 0.7% | Oct 3, 2024 | An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for... |
| CVE-2024-5803 | HIGH | 7.5 | 0.1% | Oct 3, 2024 | The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via a... |
| CVE-2024-47614 | HIGH | 7.5 | 0.6% | Oct 3, 2024 | async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of ... |
| CVE-2024-9313 | HIGH | 8.8 | 0.6% | Oct 3, 2024 | Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same b... |
| CVE-2024-8352 | HIGH | 7.5 | 0.9% | Oct 3, 2024 | The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directory... |
| CVE-2024-47136 | HIGH | 7.8 | 0.3% | Oct 3, 2024 | Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) ... |
| CVE-2024-47135 | HIGH | 7.8 | 0.3% | Oct 3, 2024 | Stack-based buffer overflow vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming S... |
| CVE-2024-47134 | HIGH | 7.8 | 0.3% | Oct 3, 2024 | Out-of-bounds write vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software)... |
| CVE-2024-28888 | HIGH | 8.8 | 1.9% | Oct 2, 2024 | A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a checkbox field object. A special... |
| CVE-2024-8733 | HIGH | 8 | 0.2% | Oct 2, 2024 | A potential security vulnerability has been identified in the HP One Agent for certain HP PC products, which might allow... |
| CVE-2024-20502 | HIGH | 7.5 | 0.5% | Oct 2, 2024 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devic... |
| CVE-2024-20501 | HIGH | 7.5 | 0.5% | Oct 2, 2024 | Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gate... |
| CVE-2024-20500 | HIGH | 7.5 | 0.6% | Oct 2, 2024 | A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devic... |
| CVE-2024-20499 | HIGH | 7.5 | 0.5% | Oct 2, 2024 | Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gate... |
| CVE-2024-20498 | HIGH | 7.5 | 0.5% | Oct 2, 2024 | Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gate... |
| CVE-2024-46626 | HIGH | 8.8 | 0.9% | Oct 2, 2024 | OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now