2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-31551HIGH7.5Directory Traversal vulnerability in lib/admin/image.admin.php in cmseasy v7.7.7.9 20240105 allows attackers to delete a...
CVE-2024-4242HIGH8.8A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been rated as critical. This issue affects the function form...
CVE-2024-4241HIGH8.8A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been declared as critical. This vulnerability affects the fu...
CVE-2024-4240HIGH8.8A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been classified as critical. This affects the function formQ...
CVE-2024-4239HIGH8.8A vulnerability was found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this issue is the function for...
CVE-2024-32883HIGH7.7MCUboot is a secure bootloader for 32-bits microcontrollers. MCUboot uses a TLV (tag-length-value) structure to represen...
CVE-2024-32878HIGH8.8Llama.cpp is LLM inference in C/C++. There is a use of uninitialized heap variable vulnerability in gguf_init_from_file,...
CVE-2024-31502HIGH8.1An issue in Insurance Management System v.1.0.0 and before allows a remote attacker to escalate privileges via a crafted...
CVE-2024-4238HIGH8.8A vulnerability has been found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this vulnerability is the...
CVE-2024-4237HIGH8.8A vulnerability, which was classified as critical, was found in Tenda AX1806 1.0.0.1. Affected is the function R7WebsSec...
CVE-2024-28327HIGH8.4Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized acce...
CVE-2024-4236HIGH8.8A vulnerability, which was classified as critical, has been found in Tenda AX1803 1.0.0.1. This issue affects the functi...
CVE-2024-33343HIGH8.8D-Link DIR-822+ V1.0.5 was found to contain a command injection in ChgSambaUserSettings function of prog.cgi, which allo...
CVE-2024-33342HIGH7.5D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows r...
CVE-2024-32880HIGH7.2pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder a...
CVE-2024-33258HIGH7.1Jerryscript commit ff9ff8f was discovered to contain a segmentation violation via the component vm_loop at jerry-core/vm...
CVE-2024-27124HIGH7.5An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2024-21905HIGH8.2An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If e...
CVE-2024-33688HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Teluro.This issue affects Teluro: from n/a through 1.0....
CVE-2024-1789HIGH7.2The WP SMTP plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in versions 1.2 to 1.2.6 due ...
CVE-2024-33651HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar : fr...
CVE-2024-4056HIGH7.5Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allow...
CVE-2024-3075HIGH8.1The MM-email2image WordPress plugin through 0.2.5 does not validate and escape some of its shortcode attributes before o...
CVE-2024-3154HIGH7.2A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can cr...
CVE-2024-32406HIGH7.5Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execut...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now