2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-35395HIGH8.8TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sampl...
CVE-2024-35618HIGH7.5PingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer.
CVE-2024-35340HIGH8.6Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at ip...
CVE-2024-4037HIGH7.3The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and i...
CVE-2024-0867HIGH8.1The Email Log plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including,...
CVE-2024-5299HIGH8.8D-Link D-View execMonitorScript Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2024-5298HIGH8.8D-Link D-View queryDeviceCustomMonitorResult Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerab...
CVE-2024-5297HIGH8.8D-Link D-View executeWmicCmd Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote att...
CVE-2024-5295HIGH8.8D-Link G416 flupl self Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent...
CVE-2024-5293HIGH8.8D-Link DIR-2640 HTTP Referer Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows ...
CVE-2024-5292HIGH7.8D-Link Network Assistant Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability a...
CVE-2024-5291HIGH8.8D-Link DIR-2150 GetDeviceSettings Target Command Injection Remote Code Execution Vulnerability. This vulnerability allow...
CVE-2024-5247HIGH8.8NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability. Th...
CVE-2024-5246HIGH8.8NETGEAR ProSAFE Network Management System Tomcat Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2024-5245HIGH7.8NETGEAR ProSAFE Network Management System Default Credentials Local Privilege Escalation Vulnerability. This vulnerabili...
CVE-2024-5243HIGH7.5TP-Link Omada ER605 Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent atta...
CVE-2024-5242HIGH7.5TP-Link Omada ER605 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-a...
CVE-2024-5228HIGH7.5TP-Link Omada ER605 Comexe DDNS Response Handling Heap-based Buffer Overflow Remote Code Execution Vulnerability. This ...
CVE-2024-5227HIGH7.5TP-Link Omada ER605 PPTP VPN username Command Injection Remote Code Execution Vulnerability. This vulnerability allows n...
CVE-2024-5202HIGH7.7Arbitrary File Read in OpenText Dimensions RM allows authenticated users to read files stored on the server via webservi...
CVE-2024-5201HIGH8.8Privilege Escalation in OpenText Dimensions RM allows an authenticated user to escalate there privilege to the privilege...
CVE-2024-35090HIGH8.2J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysUreportFileMappe...
CVE-2024-35083HIGH8.8J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysLoginInfoMapper....
CVE-2024-35081HIGH7.5LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter in th...
CVE-2024-34936HIGH8.6A SQL injection vulnerability in /view/event1.php in Campcodes Complete Web-Based School Management System 1.0 allows an...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now