2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-33659HIGH8.8AMI APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation by a local attacker...
CVE-2024-54089HIGH8.7A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All v...
CVE-2024-54015HIGH8.7A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP300) (All ve...
CVE-2024-53977HIGH7.8A vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example se...
CVE-2024-53648HIGH7A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.90), SIPROTEC 5 6MD85 (CP200) (All ve...
CVE-2024-45386HIGH8.8A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Up...
CVE-2024-13643HIGH8.8The Zox News - Professional WordPress News & Magazine Theme plugin for WordPress is vulnerable to unauthorized data modi...
CVE-2024-57177HIGH7.3A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially ...
CVE-2024-8550HIGH7.5A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4...
CVE-2024-46436HIGH8.3Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to gain root access to the ...
CVE-2024-46435HIGH8A stack overflow vulnerability in the Tenda W18E V16.01.0.8(1625) web management portal allows an authenticated remote a...
CVE-2024-46434HIGH8.8Tenda W18E V16.01.0.8(1625) suffers from authentication bypass in the web management portal allowing an unauthorized rem...
CVE-2024-46433HIGH8.8A default credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the...
CVE-2024-46432HIGH8.8Tenda W18E V16.01.0.8(1625) is vulnerable to Incorrect Access Control. An attacker can send a specially crafted HTTP POS...
CVE-2024-46431HIGH8Tenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can e...
CVE-2024-46429HIGH8.8A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access t...
CVE-2024-42512HIGH8.6Vulnerability in the OPC UA .NET Standard Stack before 1.5.374.158 allows an unauthorized attacker to bypass application...
CVE-2024-27859HIGH8.8The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14....
CVE-2024-13059HIGH7.2A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling ...
CVE-2024-57408HIGH7.2An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute...
CVE-2024-57407HIGH7.3An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrar...
CVE-2024-54954HIGH8OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.
CVE-2024-10334HIGH7.3A vulnerability exists in the VideONet product included in the listed System 800xA versions, where VideONet is used.  A...
CVE-2024-11621HIGH8.8Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to...
CVE-2024-8684HIGH8.3OS Command Injection vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now