2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-50393 | CRITICAL | 9.8 | 1.3% | Dec 6, 2024 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the ... |
| CVE-2024-50389 | CRITICAL | 9.8 | 0.8% | Dec 6, 2024 | A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote a... |
| CVE-2024-50388 | CRITICAL | 9.8 | 2.3% | Dec 6, 2024 | An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerabil... |
| CVE-2024-50387 | CRITICAL | 9.8 | 10.1% | Dec 6, 2024 | A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vuln... |
| CVE-2024-48863 | CRITICAL | 9.8 | 1.0% | Dec 6, 2024 | A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allo... |
| CVE-2024-48859 | CRITICAL | 9.1 | 0.6% | Dec 6, 2024 | An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploite... |
| CVE-2024-54750 | CRITICAL | 9.8 | 0.4% | Dec 6, 2024 | Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attacker... |
| CVE-2024-54747 | CRITICAL | 9.8 | 0.5% | Dec 6, 2024 | WAVLINK WN531P3 202383 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attacke... |
| CVE-2024-54745 | CRITICAL | 9.8 | 0.5% | Dec 6, 2024 | WAVLINK WN701AE M01AE_V240305 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows ... |
| CVE-2024-54136 | CRITICAL | 9.8 | 0.7% | Dec 6, 2024 | ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 5.5.1 Revision 199 and below is vulnera... |
| CVE-2024-54214 | CRITICAL | 10 | 0.7% | Dec 6, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in roninwp Revy revy allows Upload a Web Shell to a Web Se... |
| CVE-2024-53810 | CRITICAL | 9.1 | 0.4% | Dec 6, 2024 | Missing Authorization vulnerability in N-Media Simple User Registration wp-registration allows Accessing Functionality N... |
| CVE-2024-53807 | CRITICAL | 9.8 | 0.4% | Dec 6, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in brandtoss WP Mails... |
| CVE-2024-53805 | CRITICAL | 9.8 | 0.6% | Dec 6, 2024 | Missing Authorization vulnerability in brandtoss WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access... |
| CVE-2024-52335 | CRITICAL | 9.8 | 0.7% | Dec 6, 2024 | A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF05). The affected application do not pr... |
| CVE-2024-51815 | CRITICAL | 9 | 0.5% | Dec 6, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member allows Cod... |
| CVE-2024-51615 | CRITICAL | 9.3 | 0.4% | Dec 6, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Marka WordPress... |
| CVE-2024-10773 | CRITICAL | 9 | 0.6% | Dec 6, 2024 | The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This... |
| CVE-2024-53908 | CRITICAL | 9.8 | 1.4% | Dec 6, 2024 | An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django... |
| CVE-2024-12155 | CRITICAL | 9.8 | 1.2% | Dec 6, 2024 | The SV100 Companion plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e... |
| CVE-2024-38920 | CRITICAL | 9.1 | 0.5% | Dec 5, 2024 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via... |
| CVE-2024-37863 | CRITICAL | 9.8 | 0.6% | Dec 5, 2024 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow vi... |
| CVE-2024-37861 | CRITICAL | 9.8 | 0.6% | Dec 5, 2024 | Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow vi... |
| CVE-2024-53442 | CRITICAL | 9.8 | 1.3% | Dec 5, 2024 | whapa v1.59 is vulnerable to Command Injection via a crafted filename to the HTML reports component. |
| CVE-2024-41579 | CRITICAL | 9.8 | 0.5% | Dec 5, 2024 | DTStack Taier 1.4.0 allows remote attackers to specify the jobName parameter in the console listNames function to cause ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now