2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-45861HIGH7.5Kastle Systems firmware prior to May 1, 2024, contained a hard-coded credential, which if accessed may allow an attacker...
CVE-2024-45752HIGH7.3logiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an u...
CVE-2024-46394HIGH8.8FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add
CVE-2024-46382HIGH7.5A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via ...
CVE-2024-7254HIGH7.5Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGRO...
CVE-2024-37406HIGH7.5In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, w...
CVE-2024-46373HIGH8.8Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.
CVE-2024-44589HIGH8.8Stack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows atta...
CVE-2024-39339HIGH7.5A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota c...
CVE-2024-8287HIGH7.5Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the...
CVE-2024-34057HIGH7.5Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing re...
CVE-2024-46987HIGH7.7Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. A path traversal vulnerability ...
CVE-2024-45601HIGH7.5Mesop is a Python-based UI framework designed for rapid web apps development. A vulnerability has been discovered and fi...
CVE-2024-46086HIGH8.8FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_mana...
CVE-2024-5958HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eliz Software Pane...
CVE-2024-46598HIGH7.5Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the iprofileidx parameter at dialin.cgi. This...
CVE-2024-46597HIGH7.5Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sPubKey parameter at dialin.cgi. This vul...
CVE-2024-46596HIGH7.5Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sAct parameter at v2x00.cgi. This vulnera...
CVE-2024-46595HIGH7.5Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the saveitem parameter at lan2lan.cgi. This v...
CVE-2024-46594HIGH7.5Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the saveVPNProfile parameter at v2x00.cgi. Th...
CVE-2024-46593HIGH7.5Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the trapcomm parameter at cgiswm.cgi. This vu...
CVE-2024-46592HIGH7.5Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ssidencrypt_5g%d parameter at v2x00.cgi. ...
CVE-2024-46591HIGH7.5Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sDnsPro parameter at v2x00.cgi. This vuln...
CVE-2024-46590HIGH7.5Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ssidencrypt%d parameter at v2x00.cgi. Thi...
CVE-2024-46589HIGH7.5Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sIpv6AiccuUser parameter at inetipv6.cgi....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now