2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-40883 | HIGH | 8.8 | 0.2% | Aug 1, 2024 | Cross-site request forgery vulnerability exists in ELECOM wireless LAN routers. Viewing a malicious page while logging i... |
| CVE-2024-7331 | HIGH | 8.8 | 1.2% | Aug 1, 2024 | A vulnerability was found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as critical. Affected by this issue i... |
| CVE-2024-7327 | HIGH | 8.8 | 0.5% | Jul 31, 2024 | A vulnerability classified as critical was found in Xinhu RockOA 2.6.2. This vulnerability affects the function dataActi... |
| CVE-2024-41262 | HIGH | 7.4 | 0.2% | Jul 31, 2024 | mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly all... |
| CVE-2024-7326 | HIGH | 7.8 | 0.3% | Jul 31, 2024 | A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknow... |
| CVE-2024-41255 | HIGH | 7.5 | 0.2% | Jul 31, 2024 | filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attack... |
| CVE-2024-41253 | HIGH | 7.1 | 0.1% | Jul 31, 2024 | goframe v2.7.2 is configured to skip TLS certificate verification, possibly allowing attackers to execute a man-in-the-m... |
| CVE-2024-40465 | HIGH | 8.8 | 0.4% | Jul 31, 2024 | An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the getCacheFileName function i... |
| CVE-2024-40464 | HIGH | 8.8 | 0.6% | Jul 31, 2024 | An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located i... |
| CVE-2024-7325 | HIGH | 7.8 | 0.2% | Jul 31, 2024 | A vulnerability was found in IObit Driver Booster 11.0.0.0. It has been rated as critical. Affected by this issue is som... |
| CVE-2024-41954 | HIGH | 7.8 | 0.3% | Jul 31, 2024 | FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account cred... |
| CVE-2024-41630 | HIGH | 7.6 | 1.0% | Jul 31, 2024 | Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary cod... |
| CVE-2024-40645 | HIGH | 8.8 | 1.0% | Jul 31, 2024 | FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows a... |
| CVE-2024-7324 | HIGH | 8.5 | 0.2% | Jul 31, 2024 | A vulnerability was found in IObit iTop Data Recovery Pro 4.4.0.687. It has been declared as critical. Affected by this ... |
| CVE-2024-23444 | HIGH | 7.5 | 0.2% | Jul 31, 2024 | It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order ... |
| CVE-2024-6978 | HIGH | 8.8 | 0.1% | Jul 31, 2024 | Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP... |
| CVE-2024-6975 | HIGH | 8.8 | 0.3% | Jul 31, 2024 | Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Clien... |
| CVE-2024-6974 | HIGH | 7.8 | 0.2% | Jul 31, 2024 | Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.3... |
| CVE-2024-6973 | HIGH | 8.8 | 0.8% | Jul 31, 2024 | Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34. |
| CVE-2024-41950 | HIGH | 7.5 | 1.2% | Jul 31, 2024 | Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models, vecto... |
| CVE-2024-37901 | HIGH | 8.8 | 1.1% | Jul 31, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with e... |
| CVE-2024-7340 | HIGH | 8.8 | 5.0% | Jul 31, 2024 | The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation... |
| CVE-2024-3083 | HIGH | 8.3 | 0.2% | Jul 31, 2024 | A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations... |
| CVE-2024-31202 | HIGH | 7.8 | 0.2% | Jul 31, 2024 | A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a loca... |
| CVE-2024-7308 | HIGH | 8.8 | 0.6% | Jul 31, 2024 | A vulnerability was found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. Affe... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now