2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-7432HIGH8.8The Unseen Blog theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 vi...
CVE-2024-21489HIGH8.2Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to m...
CVE-2024-47295HIGH8.1Insecure initial password configuration issue in SEIKO EPSON Web Config allows a remote unauthenticated attacker to set ...
CVE-2024-8981HIGH7.1The Broken Link Checker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query...
CVE-2024-47560HIGH7.8RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is ex...
CVE-2024-7675HIGH7.8A maliciously crafted DWF file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Use-After-Free. A mali...
CVE-2024-7674HIGH7.8A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer O...
CVE-2024-7673HIGH7.8A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Heap-based Buffer Ove...
CVE-2024-7672HIGH7.8A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Autodesk Navisworks, may force an Out-of-Bou...
CVE-2024-7671HIGH7.8A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, may force an Out-of-Bounds Writ...
CVE-2024-7670HIGH7.8A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force an Out-of-Bounds Read. ...
CVE-2024-28813HIGH8.4An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management applicatio...
CVE-2024-28812HIGH8.8An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) w...
CVE-2024-46511HIGH7.5LoadZilla LLC LoadLogic v1.4.3 was discovered to contain insecure permissions vulnerability which allows a remote attack...
CVE-2024-28809HIGH8.8An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update package...
CVE-2024-46549HIGH7.6An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connecti...
CVE-2024-46510HIGH7.6ESAFENET CDG v5 was discovered to contain a SQL injection vulnerability via the id parameter in the NavigationAjax inter...
CVE-2024-46313HIGH8TP-Link WR941ND V6 has a stack overflow vulnerability in the ssid parameter in /userRpm/popupSiteSurveyRpm.htm.
CVE-2024-46280HIGH8.8PIX-LINK LV-WR22 RE3002-P1-01_V117.0 is vulnerable to Improper Access Control. The TELNET service is enabled with weak c...
CVE-2024-45772HIGH8Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replica...
CVE-2024-8458HIGH8.8Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CS...
CVE-2024-8454HIGH7.5The swctrl service is used to detect and remotely manage PLANET Technology devices. Certain switch models have a Denial-...
CVE-2024-6394HIGH7.5A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to un...
CVE-2024-8452HIGH7.5Certain switch models from PLANET Technology only support obsolete algorithms for authentication protocol and encryption...
CVE-2024-8451HIGH7.5Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated co...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now