2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31551 | HIGH | 7.5 | 0.7% | Apr 26, 2024 | Directory Traversal vulnerability in lib/admin/image.admin.php in cmseasy v7.7.7.9 20240105 allows attackers to delete a... |
| CVE-2024-4242 | HIGH | 8.8 | 1.3% | Apr 26, 2024 | A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been rated as critical. This issue affects the function form... |
| CVE-2024-4241 | HIGH | 8.8 | 1.3% | Apr 26, 2024 | A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been declared as critical. This vulnerability affects the fu... |
| CVE-2024-4240 | HIGH | 8.8 | 1.5% | Apr 26, 2024 | A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been classified as critical. This affects the function formQ... |
| CVE-2024-4239 | HIGH | 8.8 | 1.5% | Apr 26, 2024 | A vulnerability was found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this issue is the function for... |
| CVE-2024-32883 | HIGH | 7.7 | 0.1% | Apr 26, 2024 | MCUboot is a secure bootloader for 32-bits microcontrollers. MCUboot uses a TLV (tag-length-value) structure to represen... |
| CVE-2024-32878 | HIGH | 8.8 | 0.7% | Apr 26, 2024 | Llama.cpp is LLM inference in C/C++. There is a use of uninitialized heap variable vulnerability in gguf_init_from_file,... |
| CVE-2024-31502 | HIGH | 8.1 | 0.6% | Apr 26, 2024 | An issue in Insurance Management System v.1.0.0 and before allows a remote attacker to escalate privileges via a crafted... |
| CVE-2024-4238 | HIGH | 8.8 | 1.5% | Apr 26, 2024 | A vulnerability has been found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this vulnerability is the... |
| CVE-2024-4237 | HIGH | 8.8 | 1.5% | Apr 26, 2024 | A vulnerability, which was classified as critical, was found in Tenda AX1806 1.0.0.1. Affected is the function R7WebsSec... |
| CVE-2024-28327 | HIGH | 8.4 | 0.1% | Apr 26, 2024 | Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized acce... |
| CVE-2024-4236 | HIGH | 8.8 | 14.9% | Apr 26, 2024 | A vulnerability, which was classified as critical, has been found in Tenda AX1803 1.0.0.1. This issue affects the functi... |
| CVE-2024-33343 | HIGH | 8.8 | 8.3% | Apr 26, 2024 | D-Link DIR-822+ V1.0.5 was found to contain a command injection in ChgSambaUserSettings function of prog.cgi, which allo... |
| CVE-2024-33342 | HIGH | 7.5 | 1.6% | Apr 26, 2024 | D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows r... |
| CVE-2024-32880 | HIGH | 7.2 | 1.3% | Apr 26, 2024 | pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder a... |
| CVE-2024-33258 | HIGH | 7.1 | 0.3% | Apr 26, 2024 | Jerryscript commit ff9ff8f was discovered to contain a segmentation violation via the component vm_loop at jerry-core/vm... |
| CVE-2024-27124 | HIGH | 7.5 | 1.4% | Apr 26, 2024 | An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ... |
| CVE-2024-21905 | HIGH | 8.2 | 0.5% | Apr 26, 2024 | An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If e... |
| CVE-2024-33688 | HIGH | 8.8 | 0.2% | Apr 26, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Teluro.This issue affects Teluro: from n/a through 1.0.... |
| CVE-2024-1789 | HIGH | 7.2 | 0.5% | Apr 26, 2024 | The WP SMTP plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in versions 1.2 to 1.2.6 due ... |
| CVE-2024-33651 | HIGH | 8.8 | 0.2% | Apr 26, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar : fr... |
| CVE-2024-4056 | HIGH | 7.5 | 0.8% | Apr 26, 2024 | Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allow... |
| CVE-2024-3075 | HIGH | 8.1 | 0.6% | Apr 26, 2024 | The MM-email2image WordPress plugin through 0.2.5 does not validate and escape some of its shortcode attributes before o... |
| CVE-2024-3154 | HIGH | 7.2 | 1.4% | Apr 26, 2024 | A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can cr... |
| CVE-2024-32406 | HIGH | 7.5 | 1.1% | Apr 26, 2024 | Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execut... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now