2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32394 | HIGH | 8.8 | 12.6% | Apr 22, 2024 | An issue in ruijie.com/cn RG-RSR10-01G-T(WA)-S RSR_3.0(1)B9P2_RSR10-01G-TW-S_07150910 and RG-RSR10-01G-T(WA)-S RSR_3.0(1... |
| CVE-2024-32399 | HIGH | 7.6 | 3.2% | Apr 22, 2024 | Directory Traversal vulnerability in RaidenMAILD Mail Server v.4.9.4 and before allows a remote attacker to obtain sensi... |
| CVE-2024-32407 | HIGH | 8.8 | 1.1% | Apr 22, 2024 | An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to t... |
| CVE-2024-28699 | HIGH | 7.8 | 0.4% | Apr 22, 2024 | A buffer overflow vulnerability in pdf2json v0.70 allows a local attacker to execute arbitrary code via the GString::cop... |
| CVE-2024-32368 | HIGH | 7.3 | 0.3% | Apr 22, 2024 | Insecure Permission vulnerability in Agasta Sanketlife 2.0 Pocket 12-Lead ECG Monitor FW Version 3.0 allows a local atta... |
| CVE-2024-22811 | HIGH | 8.2 | 0.4% | Apr 22, 2024 | An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) b... |
| CVE-2024-22808 | HIGH | 7.5 | 0.5% | Apr 22, 2024 | An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) b... |
| CVE-2024-32684 | HIGH | 7.5 | 0.4% | Apr 22, 2024 | Missing Authorization vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through ... |
| CVE-2024-32682 | HIGH | 8.8 | 0.5% | Apr 22, 2024 | Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Ad... |
| CVE-2024-32681 | HIGH | 8.8 | 0.4% | Apr 22, 2024 | Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Ad... |
| CVE-2024-32695 | HIGH | 7.1 | 0.4% | Apr 22, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Gasi Languag... |
| CVE-2024-32694 | HIGH | 7.1 | 0.4% | Apr 22, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative interacti... |
| CVE-2024-32693 | HIGH | 7.6 | 0.2% | Apr 22, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in ValvePress Automatic.This issue affects Automatic: from n/a before 3.... |
| CVE-2024-4020 | HIGH | 8.8 | 1.6% | Apr 20, 2024 | A vulnerability was found in Tenda FH1206 1.2.0.8(8155) and classified as critical. This issue affects the function from... |
| CVE-2024-1480 | HIGH | 7.5 | 0.5% | Apr 19, 2024 | Unitronics Vision Standard line of controllers allow the Information Mode password to be retrieved without authenticatio... |
| CVE-2024-4018 | HIGH | 7.8 | 0.2% | Apr 19, 2024 | Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api mo... |
| CVE-2024-4017 | HIGH | 7.8 | 0.2% | Apr 19, 2024 | Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (filesystem modules) al... |
| CVE-2024-32391 | HIGH | 7.3 | 0.9% | Apr 19, 2024 | Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code vi... |
| CVE-2024-30974 | HIGH | 7.3 | 0.3% | Apr 19, 2024 | SQL Injection vulnerability in autoexpress v.1.3.0 allows attackers to run arbitrary SQL commands via the carId paramete... |
| CVE-2024-22905 | HIGH | 7 | 0.4% | Apr 19, 2024 | Buffer Overflow vulnerability in ARM mbed-os v.6.17.0 allows a remote attacker to execute arbitrary code via a crafted s... |
| CVE-2024-32652 | HIGH | 7.5 | 0.9% | Apr 19, 2024 | The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs... |
| CVE-2024-31552 | HIGH | 7.1 | 0.2% | Apr 19, 2024 | CuteHttpFileServer v.3.1 version has an arbitrary file download vulnerability, which allows attackers to download arbitr... |
| CVE-2024-32650 | HIGH | 7.5 | 0.9% | Apr 19, 2024 | Rustls is a modern TLS library written in Rust. `rustls::ConnectionCommon::complete_io` could fall into an infinite loop... |
| CVE-2024-32409 | HIGH | 7.1 | 0.7% | Apr 19, 2024 | An issue in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code via a crafted script. |
| CVE-2024-31846 | HIGH | 7.5 | 0.7% | Apr 19, 2024 | An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now