2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-41589HIGH8.8DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.
CVE-2024-41588HIGH8The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflo...
CVE-2024-41586HIGH8A stack-based Buffer Overflow vulnerability in DrayTek Vigor310 devices through 4.3.2.6 allows a remote attacker to exec...
CVE-2024-41987HIGH8.6The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests...
CVE-2024-42415HIGH7.8An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Pro...
CVE-2024-41922HIGH7.5A directory traversal vulnerability exists in the log files download functionality of Veertu Anka Build 1.42.0. A specia...
CVE-2024-41163HIGH7.5A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. A specially crafted...
CVE-2024-39755HIGH7.8A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially cr...
CVE-2024-36474HIGH7.8An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Struc...
CVE-2024-25590HIGH7.5An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for...
CVE-2024-5803HIGH7.5The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via a...
CVE-2024-47614HIGH7.5async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of ...
CVE-2024-9313HIGH8.8Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same b...
CVE-2024-8352HIGH7.5The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directory...
CVE-2024-47136HIGH7.8Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) ...
CVE-2024-47135HIGH7.8Stack-based buffer overflow vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming S...
CVE-2024-47134HIGH7.8Out-of-bounds write vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software)...
CVE-2024-28888HIGH8.8A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a checkbox field object. A special...
CVE-2024-8733HIGH8A potential security vulnerability has been identified in the HP One Agent for certain HP PC products, which might allow...
CVE-2024-20502HIGH7.5A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devic...
CVE-2024-20501HIGH7.5Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gate...
CVE-2024-20500HIGH7.5A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devic...
CVE-2024-20499HIGH7.5Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gate...
CVE-2024-20498HIGH7.5Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gate...
CVE-2024-46626HIGH8.8OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now