2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-51252CRITICAL9.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-48353HIGH7.5Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and ...
CVE-2024-51492HIGH8.8Zusam is a free and open-source way to self-host private forums. Prior to version 0.5.6, specially crafted SVG files upl...
CVE-2024-51483MEDIUM6.9changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is...
CVE-2024-51431CRITICAL9.8LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.
CVE-2024-51248HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51247HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51245HIGH8.8In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51244HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-49770HIGH7.7`oak` is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers a...
CVE-2024-48410MEDIUM6.1Cross Site Scripting vulnerability in Camtrace v.9.16.2.1 allows a remote attacker to execute arbitrary code via the log...
CVE-2024-48352HIGH7.5Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTT...
CVE-2024-48217HIGH8.8An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-p...
CVE-2024-41745MEDIUM6.1IBM CICS TX Standard is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to emb...
CVE-2024-41744HIGH8.8IBM CICS TX Standard 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious...
CVE-2024-41741MEDIUM5.3IBM TXSeries for Multiplatforms 10.1 could allow an attacker to determine valid usernames due to an observable timing di...
CVE-2024-41738MEDIUM5.9IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an...
CVE-2024-51432MEDIUM4.8Cross Site Scripting vulnerability in FiberHome HG6544C RP2743 allows an attacker to execute arbitrary code via the SSID...
CVE-2024-51399MEDIUM5.7Altai Technologies Ltd Altai IX500 Indoor 22 802.11ac Wave 2 AP After login, there are file reads in the background, and...
CVE-2024-51398MEDIUM6.5Altai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management Weak password leakage in the background ma...
CVE-2024-51377MEDIUM5.4An issue in Ladybird Web Solution Faveo Helpdesk & Servicedesk (On-Premise and Cloud) 9.2.0 allows a remote attacker to ...
CVE-2024-40490HIGH7.5An issue in Sourcebans++ before v.1.8.0 allows a remote attacker to obtain sensitive information via a crafted XAJAX cal...
CVE-2024-28265CRITICAL9.1IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.
CVE-2024-22733HIGH7.5TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration ...
CVE-2024-10662HIGH8.8A vulnerability was found in Tenda AC15 15.03.05.19 and classified as critical. This issue affects the function formSetD...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now