2024 CVE Vulnerabilities
39,257 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45861 | HIGH | 7.5 | 0.4% | Sep 19, 2024 | Kastle Systems firmware prior to May 1, 2024, contained a hard-coded credential, which if accessed may allow an attacker... |
| CVE-2024-45752 | HIGH | 7.3 | 0.3% | Sep 19, 2024 | logiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an u... |
| CVE-2024-46394 | HIGH | 8.8 | 0.3% | Sep 19, 2024 | FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add |
| CVE-2024-46382 | HIGH | 7.5 | 0.6% | Sep 19, 2024 | A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via ... |
| CVE-2024-7254 | HIGH | 7.5 | 2.8% | Sep 19, 2024 | Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGRO... |
| CVE-2024-37406 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, w... |
| CVE-2024-46373 | HIGH | 8.8 | 0.5% | Sep 18, 2024 | Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend. |
| CVE-2024-44589 | HIGH | 8.8 | 0.9% | Sep 18, 2024 | Stack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows atta... |
| CVE-2024-39339 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota c... |
| CVE-2024-8287 | HIGH | 7.5 | 0.2% | Sep 18, 2024 | Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the... |
| CVE-2024-34057 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing re... |
| CVE-2024-46987 | HIGH | 7.7 | 14.6% | Sep 18, 2024 | Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. A path traversal vulnerability ... |
| CVE-2024-45601 | HIGH | 7.5 | 0.3% | Sep 18, 2024 | Mesop is a Python-based UI framework designed for rapid web apps development. A vulnerability has been discovered and fi... |
| CVE-2024-46086 | HIGH | 8.8 | 0.3% | Sep 18, 2024 | FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_mana... |
| CVE-2024-5958 | HIGH | 8.8 | 0.5% | Sep 18, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eliz Software Pane... |
| CVE-2024-46598 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the iprofileidx parameter at dialin.cgi. This... |
| CVE-2024-46597 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sPubKey parameter at dialin.cgi. This vul... |
| CVE-2024-46596 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sAct parameter at v2x00.cgi. This vulnera... |
| CVE-2024-46595 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the saveitem parameter at lan2lan.cgi. This v... |
| CVE-2024-46594 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the saveVPNProfile parameter at v2x00.cgi. Th... |
| CVE-2024-46593 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the trapcomm parameter at cgiswm.cgi. This vu... |
| CVE-2024-46592 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ssidencrypt_5g%d parameter at v2x00.cgi. ... |
| CVE-2024-46591 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sDnsPro parameter at v2x00.cgi. This vuln... |
| CVE-2024-46590 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ssidencrypt%d parameter at v2x00.cgi. Thi... |
| CVE-2024-46589 | HIGH | 7.5 | 0.4% | Sep 18, 2024 | Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sIpv6AiccuUser parameter at inetipv6.cgi.... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now