2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-47654HIGH7.5This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP request...
CVE-2024-47652HIGH8.1This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the...
CVE-2024-6400HIGH7.5Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finr...
CVE-2024-47850HIGH7.5CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a sing...
CVE-2024-42417HIGH8.8Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker...
CVE-2024-46658HIGH8Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.
CVE-2024-41596HIGH8Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because o...
CVE-2024-41595HIGH8DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cg...
CVE-2024-41594HIGH7.5An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the http...
CVE-2024-41592HIGH8DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because Ge...
CVE-2024-41590HIGH8Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on ...
CVE-2024-41589HIGH8.8DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.
CVE-2024-41588HIGH8The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflo...
CVE-2024-41586HIGH8A stack-based Buffer Overflow vulnerability in DrayTek Vigor310 devices through 4.3.2.6 allows a remote attacker to exec...
CVE-2024-41987HIGH8.6The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests...
CVE-2024-42415HIGH7.8An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Pro...
CVE-2024-41922HIGH7.5A directory traversal vulnerability exists in the log files download functionality of Veertu Anka Build 1.42.0. A specia...
CVE-2024-41163HIGH7.5A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. A specially crafted...
CVE-2024-39755HIGH7.8A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially cr...
CVE-2024-36474HIGH7.8An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Struc...
CVE-2024-25590HIGH7.5An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for...
CVE-2024-5803HIGH7.5The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via a...
CVE-2024-47614HIGH7.5async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of ...
CVE-2024-9313HIGH8.8Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same b...
CVE-2024-8352HIGH7.5The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directory...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now