2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-44390HIGH8.8Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset.
CVE-2024-39841HIGH8.8A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, ...
CVE-2024-44386HIGH7.3Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind.
CVE-2024-42756HIGH8.8An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page
CVE-2024-42636HIGH7.2DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.
CVE-2024-42523HIGH7.2publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData
CVE-2024-43791HIGH7.8RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 ...
CVE-2024-42915HIGH8A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token...
CVE-2024-42040HIGH8.1Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today o...
CVE-2024-37311HIGH8.2Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, ...
CVE-2024-5586HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet loc...
CVE-2024-5556HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports modu...
CVE-2024-5490HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate re...
CVE-2024-5467HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lock...
CVE-2024-5466HIGH8.8Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the aut...
CVE-2024-36517HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts modul...
CVE-2024-36516HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. N...
CVE-2024-36515HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. N...
CVE-2024-36514HIGH8.8Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary...
CVE-2024-43883HIGH7In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new re...
CVE-2024-7986HIGH7.5A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensiti...
CVE-2024-7258HIGH8.8The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing cap...
CVE-2024-7559HIGH8.8The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation an...
CVE-2024-43477HIGH7.5Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated at...
CVE-2024-38210HIGH7.8Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now