2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-40883HIGH8.8Cross-site request forgery vulnerability exists in ELECOM wireless LAN routers. Viewing a malicious page while logging i...
CVE-2024-7331HIGH8.8A vulnerability was found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as critical. Affected by this issue i...
CVE-2024-7327HIGH8.8A vulnerability classified as critical was found in Xinhu RockOA 2.6.2. This vulnerability affects the function dataActi...
CVE-2024-41262HIGH7.4mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly all...
CVE-2024-7326HIGH7.8A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknow...
CVE-2024-41255HIGH7.5filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attack...
CVE-2024-41253HIGH7.1goframe v2.7.2 is configured to skip TLS certificate verification, possibly allowing attackers to execute a man-in-the-m...
CVE-2024-40465HIGH8.8An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the getCacheFileName function i...
CVE-2024-40464HIGH8.8An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located i...
CVE-2024-7325HIGH7.8A vulnerability was found in IObit Driver Booster 11.0.0.0. It has been rated as critical. Affected by this issue is som...
CVE-2024-41954HIGH7.8FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account cred...
CVE-2024-41630HIGH7.6Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary cod...
CVE-2024-40645HIGH8.8FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows a...
CVE-2024-7324HIGH8.5A vulnerability was found in IObit iTop Data Recovery Pro 4.4.0.687. It has been declared as critical. Affected by this ...
CVE-2024-23444HIGH7.5It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order ...
CVE-2024-6978HIGH8.8Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP...
CVE-2024-6975HIGH8.8Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Clien...
CVE-2024-6974HIGH7.8Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.3...
CVE-2024-6973HIGH8.8Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34.
CVE-2024-41950HIGH7.5Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models, vecto...
CVE-2024-37901HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with e...
CVE-2024-7340HIGH8.8The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation...
CVE-2024-3083HIGH8.3A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations...
CVE-2024-31202HIGH7.8A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a loca...
CVE-2024-7308HIGH8.8A vulnerability was found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. Affe...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now