2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49414 | LOW | 2.4 | 0.2% | Dec 3, 2024 | Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to t... |
| CVE-2024-49413 | HIGH | 7.8 | 0.2% | Dec 3, 2024 | Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers t... |
| CVE-2024-49412 | MEDIUM | 5.5 | 0.1% | Dec 3, 2024 | Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for dis... |
| CVE-2024-49411 | MEDIUM | 4.6 | 0.2% | Dec 3, 2024 | Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary p... |
| CVE-2024-49410 | HIGH | 7.8 | 0.2% | Dec 3, 2024 | Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary c... |
| CVE-2024-10893 | MEDIUM | 4.8 | 0.3% | Dec 3, 2024 | The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could al... |
| CVE-2024-10484 | MEDIUM | 5.4 | 0.3% | Dec 3, 2024 | The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-9694 | MEDIUM | 6.4 | 0.3% | Dec 3, 2024 | The CMSMasters Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in... |
| CVE-2024-45068 | HIGH | 7.1 | 0.3% | Dec 3, 2024 | Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. ... |
| CVE-2024-9200 | HIGH | 7.2 | 1.1% | Dec 3, 2024 | A post-authentication command injection vulnerability in the "host" parameter of the diagnostic function in Zyxel VMG400... |
| CVE-2024-9197 | MEDIUM | 4.9 | 0.5% | Dec 3, 2024 | A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B f... |
| CVE-2024-8748 | HIGH | 7.5 | 0.5% | Dec 3, 2024 | A buffer overflow vulnerability in the packet parser of the third-party library "libclinkc" in Zyxel VMG8825-T50K firmwa... |
| CVE-2024-53937 | HIGH | 8.8 | 0.4% | Dec 2, 2024 | An issue was discovered on Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNE... |
| CVE-2024-53988 | MEDIUM | 6.1 | 0.4% | Dec 2, 2024 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera... |
| CVE-2024-53987 | MEDIUM | 6.1 | 0.4% | Dec 2, 2024 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera... |
| CVE-2024-53986 | MEDIUM | 6.1 | 0.5% | Dec 2, 2024 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera... |
| CVE-2024-53985 | MEDIUM | 6.1 | 0.6% | Dec 2, 2024 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera... |
| CVE-2024-53941 | HIGH | 8.8 | 0.5% | Dec 2, 2024 | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. A remote ... |
| CVE-2024-53940 | HIGH | 8.8 | 2.2% | Dec 2, 2024 | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. Certain /... |
| CVE-2024-53939 | HIGH | 8.8 | 2.8% | Dec 2, 2024 | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The /cgi-... |
| CVE-2024-53938 | HIGH | 8.8 | 0.5% | Dec 2, 2024 | An issue was discovered in Victure RX1800 WiFi 6 Router (software EN_V1.0.0_r12_110933, hardware 1.0) devices. The TELNE... |
| CVE-2024-53375 | HIGH | 8 | 40.7% | Dec 2, 2024 | An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exi... |
| CVE-2024-53989 | MEDIUM | 6.1 | 0.5% | Dec 2, 2024 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera... |
| CVE-2024-53477 | CRITICAL | 9.8 | 0.8% | Dec 2, 2024 | JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.ja... |
| CVE-2024-49581 | MEDIUM | 6.5 | 0.4% | Dec 2, 2024 | Restricted Views backed objects (OSV1) could be bypassed under specific circumstances due to a software bug, this could ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now