2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35395 | HIGH | 8.8 | 0.5% | May 24, 2024 | TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sampl... |
| CVE-2024-35618 | HIGH | 7.5 | 0.4% | May 24, 2024 | PingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer. |
| CVE-2024-35340 | HIGH | 8.6 | 1.2% | May 24, 2024 | Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at ip... |
| CVE-2024-4037 | HIGH | 7.3 | 0.5% | May 24, 2024 | The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and i... |
| CVE-2024-0867 | HIGH | 8.1 | 0.8% | May 24, 2024 | The Email Log plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including,... |
| CVE-2024-5299 | HIGH | 8.8 | 1.8% | May 23, 2024 | D-Link D-View execMonitorScript Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows ... |
| CVE-2024-5298 | HIGH | 8.8 | 1.8% | May 23, 2024 | D-Link D-View queryDeviceCustomMonitorResult Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerab... |
| CVE-2024-5297 | HIGH | 8.8 | 1.9% | May 23, 2024 | D-Link D-View executeWmicCmd Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote att... |
| CVE-2024-5295 | HIGH | 8.8 | 2.0% | May 23, 2024 | D-Link G416 flupl self Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent... |
| CVE-2024-5293 | HIGH | 8.8 | 1.6% | May 23, 2024 | D-Link DIR-2640 HTTP Referer Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ... |
| CVE-2024-5292 | HIGH | 7.8 | 0.5% | May 23, 2024 | D-Link Network Assistant Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability a... |
| CVE-2024-5291 | HIGH | 8.8 | 2.0% | May 23, 2024 | D-Link DIR-2150 GetDeviceSettings Target Command Injection Remote Code Execution Vulnerability. This vulnerability allow... |
| CVE-2024-5247 | HIGH | 8.8 | 26.9% | May 23, 2024 | NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. Th... |
| CVE-2024-5246 | HIGH | 8.8 | 31.3% | May 23, 2024 | NETGEAR ProSAFE Network Management System Tomcat Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2024-5245 | HIGH | 7.8 | 0.6% | May 23, 2024 | NETGEAR ProSAFE Network Management System Default Credentials Local Privilege Escalation Vulnerability. This vulnerabili... |
| CVE-2024-5243 | HIGH | 7.5 | 0.8% | May 23, 2024 | TP-Link Omada ER605 Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent atta... |
| CVE-2024-5242 | HIGH | 7.5 | 0.8% | May 23, 2024 | TP-Link Omada ER605 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-a... |
| CVE-2024-5228 | HIGH | 7.5 | 0.5% | May 23, 2024 | TP-Link Omada ER605 Comexe DDNS Response Handling Heap-based Buffer Overflow Remote Code Execution Vulnerability. This ... |
| CVE-2024-5227 | HIGH | 7.5 | 0.7% | May 23, 2024 | TP-Link Omada ER605 PPTP VPN username Command Injection Remote Code Execution Vulnerability. This vulnerability allows n... |
| CVE-2024-5202 | HIGH | 7.7 | 0.4% | May 23, 2024 | Arbitrary File Read in OpenText Dimensions RM allows authenticated users to read files stored on the server via webservi... |
| CVE-2024-5201 | HIGH | 8.8 | 0.4% | May 23, 2024 | Privilege Escalation in OpenText Dimensions RM allows an authenticated user to escalate there privilege to the privilege... |
| CVE-2024-35090 | HIGH | 8.2 | 0.3% | May 23, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysUreportFileMappe... |
| CVE-2024-35083 | HIGH | 8.8 | 0.4% | May 23, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysLoginInfoMapper.... |
| CVE-2024-35081 | HIGH | 7.5 | 0.5% | May 23, 2024 | LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter in th... |
| CVE-2024-34936 | HIGH | 8.6 | 0.4% | May 23, 2024 | A SQL injection vulnerability in /view/event1.php in Campcodes Complete Web-Based School Management System 1.0 allows an... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now