2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-49414LOW2.4Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to t...
CVE-2024-49413HIGH7.8Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers t...
CVE-2024-49412MEDIUM5.5Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for dis...
CVE-2024-49411MEDIUM4.6Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary p...
CVE-2024-49410HIGH7.8Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary c...
CVE-2024-10893MEDIUM4.8The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could al...
CVE-2024-10484MEDIUM5.4The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-9694MEDIUM6.4The CMSMasters Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in...
CVE-2024-45068HIGH7.1Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. ...
CVE-2024-9200HIGH7.2A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG400...
CVE-2024-9197MEDIUM4.9A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B f...
CVE-2024-8748HIGH7.5A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmwa...
CVE-2024-53937HIGH8.8An issue was discovered on Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNE...
CVE-2024-53988MEDIUM6.1rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera...
CVE-2024-53987MEDIUM6.1rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera...
CVE-2024-53986MEDIUM6.1rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera...
CVE-2024-53985MEDIUM6.1rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera...
CVE-2024-53941HIGH8.8An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. A remote ...
CVE-2024-53940HIGH8.8An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. Certain /...
CVE-2024-53939HIGH8.8An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-...
CVE-2024-53938HIGH8.8An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNE...
CVE-2024-53375HIGH8An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exi...
CVE-2024-53989MEDIUM6.1rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera...
CVE-2024-53477CRITICAL9.8JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.ja...
CVE-2024-49581MEDIUM6.5Restricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now