2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51727 | HIGH | 7.5 | 0.5% | Dec 6, 2024 | Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a feature that could enable attackers to inval... |
| CVE-2024-48871 | CRITICAL | 9.8 | 1.4% | Dec 6, 2024 | The affected product is vulnerable to a stack-based buffer overflow. An unauthenticated attacker could send a malicious ... |
| CVE-2024-48703 | MEDIUM | 4.8 | 0.3% | Dec 6, 2024 | PhpGurukul Medical Card Generation System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/search-medicalcard.... |
| CVE-2024-47547 | CRITICAL | 9.8 | 0.7% | Dec 6, 2024 | Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for its users to change their... |
| CVE-2024-47043 | MEDIUM | 5.3 | 0.4% | Dec 6, 2024 | Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could enable an attacker to correlate a device serial n... |
| CVE-2024-42494 | HIGH | 7.5 | 0.4% | Dec 6, 2024 | Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a a feature that could enable sub accounts or ... |
| CVE-2024-11220 | HIGH | 7.8 | 0.1% | Dec 6, 2024 | A local low-level user on the server machine with credentials to the running OAS services can create and execute a repor... |
| CVE-2024-55268 | MEDIUM | 6.1 | 0.4% | Dec 6, 2024 | A Reflected Cross Site Scripting (XSS) vulnerability was found in /covidtms/registered-user-testing.php in PHPGurukul CO... |
| CVE-2024-54749 | HIGH | 7.5 | 0.2% | Dec 6, 2024 | Ubiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attacke... |
| CVE-2024-54143 | CRITICAL | 9.3 | 1.9% | Dec 6, 2024 | openwrt/asu is an image on demand server for OpenWrt based distributions. The request hashing mechanism truncates SHA-25... |
| CVE-2024-53691 | HIGH | 8.8 | 20.1% | Dec 6, 2024 | A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul... |
| CVE-2024-50404 | HIGH | 8.8 | 1.4% | Dec 6, 2024 | A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow re... |
| CVE-2024-50403 | HIGH | 7.2 | 0.5% | Dec 6, 2024 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2024-50402 | HIGH | 7.2 | 0.5% | Dec 6, 2024 | A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2024-50393 | CRITICAL | 9.8 | 1.3% | Dec 6, 2024 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the ... |
| CVE-2024-50389 | CRITICAL | 9.8 | 0.8% | Dec 6, 2024 | A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote a... |
| CVE-2024-50388 | CRITICAL | 9.8 | 2.3% | Dec 6, 2024 | An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerabil... |
| CVE-2024-50387 | CRITICAL | 9.8 | 10.1% | Dec 6, 2024 | A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vuln... |
| CVE-2024-48868 | HIGH | 7.5 | 0.4% | Dec 6, 2024 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o... |
| CVE-2024-48867 | HIGH | 7.5 | 0.5% | Dec 6, 2024 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP o... |
| CVE-2024-48866 | MEDIUM | 5.3 | 0.4% | Dec 6, 2024 | An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating sys... |
| CVE-2024-48865 | HIGH | 7.5 | 0.2% | Dec 6, 2024 | An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If ... |
| CVE-2024-48863 | CRITICAL | 9.8 | 1.0% | Dec 6, 2024 | A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allo... |
| CVE-2024-48859 | CRITICAL | 9.1 | 0.6% | Dec 6, 2024 | An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploite... |
| CVE-2024-54750 | CRITICAL | 9.8 | 0.4% | Dec 6, 2024 | Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attacker... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now