2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-36650HIGH7.5TOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware A3100R V4.1.2cu.5247_B20211129, in the cgi function `setNotic...
CVE-2024-37295HIGH7.2Aimeos is an Open Source e-commerce framework for online shops. Starting in version 2024.01.1 and prior to version 2024....
CVE-2024-26010HIGH7.5A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, Fo...
CVE-2024-24703HIGH8.6Missing Authorization vulnerability in MultiVendorX WC Marketplace.This issue affects WC Marketplace: from n/a through 4...
CVE-2024-23110HIGH7.8A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13...
CVE-2024-28021HIGH7.4A vulnerability exists in the FOXMAN-UN/UNEM server that affects the message queueing mechanism’s certificate validatio...
CVE-2024-5702HIGH7.5Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects ...
CVE-2024-5700HIGH7Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidenc...
CVE-2024-5696HIGH8.6By manipulating the text in an `<input>` tag, an attacker could have caused corrupt memory leading to a potentiall...
CVE-2024-5694HIGH7.5An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section ...
CVE-2024-5688HIGH8.1If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. ...
CVE-2024-36266HIGH7.8A vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects...
CVE-2024-35303HIGH7.8A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0012), Tecnomatix Plant S...
CVE-2024-35292HIGH8.8A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200...
CVE-2024-35207HIGH7.8A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interf...
CVE-2024-35206HIGH8.5A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected a...
CVE-2024-33500HIGH7.4A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.11.0), Mendix Application...
CVE-2024-35716HIGH8.8Missing Authorization vulnerability in Copymatic Copymatic – AI Content Writer & Generator.This issue affects Copymatic ...
CVE-2024-35692HIGH7.3Missing Authorization vulnerability in Termly Cookie Consent.This issue affects Cookie Consent: from n/a through 3.2.
CVE-2024-4266HIGH7.5The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sens...
CVE-2024-34688HIGH7.5Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS att...
CVE-2024-37177HIGH8.1SAP Financial Consolidation allows data to enter a Web application through an untrusted source. These endpoints are expo...
CVE-2024-37130HIGH7.8Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability v...
CVE-2024-37289HIGH7.8An improper access control vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on ...
CVE-2024-37166HIGH8.9ghtml is software that uses tagged templates for template engine functionality. It is possible to introduce user-control...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now