2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22311 | HIGH | 7.1 | 0.4% | Mar 27, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N Squared Simply S... |
| CVE-2024-22300 | HIGH | 7.1 | 0.4% | Mar 27, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Email Subs... |
| CVE-2024-22299 | HIGH | 7.1 | 0.4% | Mar 27, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision: Makin... |
| CVE-2024-22149 | HIGH | 7.1 | 0.4% | Mar 27, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bas... |
| CVE-2024-2203 | HIGH | 8.8 | 0.6% | Mar 27, 2024 | The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ... |
| CVE-2024-2097 | HIGH | 7.5 | 0.5% | Mar 27, 2024 | An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM serv... |
| CVE-2024-25736 | HIGH | 7.5 | 4.3% | Mar 27, 2024 | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /d... |
| CVE-2024-25734 | HIGH | 7.5 | 4.1% | Mar 27, 2024 | An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only a... |
| CVE-2024-25395 | HIGH | 8.8 | 1.0% | Mar 27, 2024 | A buffer overflow occurs in utilities/rt-link/src/rtlink.c in RT-Thread through 5.0.2. |
| CVE-2024-25391 | HIGH | 8.4 | 0.3% | Mar 27, 2024 | A stack buffer overflow occurs in libc/posix/ipc/mqueue.c in RT-Thread through 5.0.2. |
| CVE-2024-25390 | HIGH | 8.4 | 0.3% | Mar 27, 2024 | A heap buffer overflow occurs in finsh/msh_file.c and finsh/msh.c in RT-Thread through 5.0.2. |
| CVE-2024-25389 | HIGH | 7.5 | 0.8% | Mar 27, 2024 | RT-Thread through 5.0.2 generates random numbers with a weak algorithm of "seed = 214013L * seed + 2531011L; return (see... |
| CVE-2024-25388 | HIGH | 8.4 | 0.3% | Mar 27, 2024 | drivers/wlan/wlan_mgmt,c in RT-Thread through 5.0.2 has an integer signedness error and resultant buffer overflow. |
| CVE-2024-24335 | HIGH | 8.4 | 0.4% | Mar 27, 2024 | A heap buffer overflow occurs in the dfs_v2 romfs filesystem RT-Thread through 5.0.2. |
| CVE-2024-24334 | HIGH | 8.4 | 0.4% | Mar 27, 2024 | A heap buffer overflow occurs in dfs_v2 dfs_file in RT-Thread through 5.0.2. |
| CVE-2024-0400 | HIGH | 7.5 | 0.6% | Mar 27, 2024 | SCM Software is a client and server application. An Authenticated System manager client can execute LINQ query in the SC... |
| CVE-2024-1531 | HIGH | 8.2 | 0.4% | Mar 27, 2024 | A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A... |
| CVE-2024-2932 | HIGH | 7.5 | 0.6% | Mar 27, 2024 | A vulnerability classified as critical has been found in SourceCodester Online Chatting System 1.0. Affected is an unkno... |
| CVE-2024-26577 | HIGH | 7.5 | 0.6% | Mar 26, 2024 | VSeeFace through 1.13.38.c2 allows attackers to cause a denial of service (application hang) via a spoofed UDP packet co... |
| CVE-2024-25136 | HIGH | 7.5 | 0.6% | Mar 26, 2024 | There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL witho... |
| CVE-2024-2910 | HIGH | 8.8 | 3.7% | Mar 26, 2024 | A vulnerability, which was classified as critical, has been found in Ruijie RG-EG350 up to 20240318. Affected by this is... |
| CVE-2024-2909 | HIGH | 8.8 | 4.0% | Mar 26, 2024 | A vulnerability classified as critical was found in Ruijie RG-EG350 up to 20240318. Affected by this vulnerability is th... |
| CVE-2024-2903 | HIGH | 8.8 | 1.8% | Mar 26, 2024 | A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function GetPare... |
| CVE-2024-2887 | HIGH | 7.7 | 19.9% | Mar 26, 2024 | Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary cod... |
| CVE-2024-2886 | HIGH | 7.5 | 2.1% | Mar 26, 2024 | Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now