2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-37882HIGH8.1Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshar...
CVE-2024-37645HIGH8.8TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter...
CVE-2024-37643HIGH8.8TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter...
CVE-2024-37641HIGH8.8TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow via the submit-url parameter at /formNewSc...
CVE-2024-37644HIGH8.8TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, w...
CVE-2024-37368HIGH7.5A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a u...
CVE-2024-37367HIGH7.5A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows...
CVE-2024-37313HIGH7.5Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second fa...
CVE-2024-34694HIGH8.1LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal ...
CVE-2024-33377HIGH8.1LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attacker...
CVE-2024-37640HIGH8.8TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWiFiEasyG...
CVE-2024-37639HIGH8.8TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via eport in the function setIpPortFilt...
CVE-2024-2024HIGH8.8The Folders Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ...
CVE-2024-36459HIGH8.4A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for ...
CVE-2024-5685HIGH8.1Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes ...
CVE-2024-5995HIGH8.8The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the sessi...
CVE-2024-31163HIGH7.2ASUS Download Master has a buffer overflow vulnerability. An unauthenticated remote attacker with administrative privile...
CVE-2024-31162HIGH7.2The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote a...
CVE-2024-5551HIGH8.8The WP STAGING Pro WordPress Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi...
CVE-2024-3498HIGH7.8Attackers can then execute malicious files by enabling certain services of the printer via the web configuration page an...
CVE-2024-3497HIGH8.8Path traversal vulnerability in the web server of the Toshiba printer enables attacker to overwrite orginal files or add...
CVE-2024-3496HIGH8.8Attackers can bypass the web login authentication process to gain access to the printer's system information and upload ...
CVE-2024-1094HIGH7.3The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress...
CVE-2024-31161HIGH7.2The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrati...
CVE-2024-27178HIGH7.2An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying file name var...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now