2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-51252 | CRITICAL | 9.8 | 0.8% | Nov 1, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-48353 | HIGH | 7.5 | 0.4% | Nov 1, 2024 | Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and ... |
| CVE-2024-51492 | HIGH | 8.8 | 0.5% | Nov 1, 2024 | Zusam is a free and open-source way to self-host private forums. Prior to version 0.5.6, specially crafted SVG files upl... |
| CVE-2024-51483 | MEDIUM | 6.9 | 2.3% | Nov 1, 2024 | changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is... |
| CVE-2024-51431 | CRITICAL | 9.8 | 0.6% | Nov 1, 2024 | LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable. |
| CVE-2024-51248 | HIGH | 8.8 | 0.8% | Nov 1, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51247 | HIGH | 8.8 | 0.8% | Nov 1, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51245 | HIGH | 8.8 | 0.8% | Nov 1, 2024 | In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51244 | HIGH | 8.8 | 0.8% | Nov 1, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-49770 | HIGH | 7.7 | 0.7% | Nov 1, 2024 | `oak` is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers a... |
| CVE-2024-48410 | MEDIUM | 6.1 | 0.4% | Nov 1, 2024 | Cross Site Scripting vulnerability in Camtrace v.9.16.2.1 allows a remote attacker to execute arbitrary code via the log... |
| CVE-2024-48352 | HIGH | 7.5 | 0.5% | Nov 1, 2024 | Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTT... |
| CVE-2024-48217 | HIGH | 8.8 | 0.7% | Nov 1, 2024 | An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-p... |
| CVE-2024-41745 | MEDIUM | 6.1 | 0.3% | Nov 1, 2024 | IBM CICS TX Standard is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to emb... |
| CVE-2024-41744 | HIGH | 8.8 | 0.2% | Nov 1, 2024 | IBM CICS TX Standard 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious... |
| CVE-2024-41741 | MEDIUM | 5.3 | 0.3% | Nov 1, 2024 | IBM TXSeries for Multiplatforms 10.1 could allow an attacker to determine valid usernames due to an observable timing di... |
| CVE-2024-41738 | MEDIUM | 5.9 | 0.3% | Nov 1, 2024 | IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an... |
| CVE-2024-51432 | MEDIUM | 4.8 | 0.3% | Nov 1, 2024 | Cross Site Scripting vulnerability in FiberHome HG6544C RP2743 allows an attacker to execute arbitrary code via the SSID... |
| CVE-2024-51399 | MEDIUM | 5.7 | 0.2% | Nov 1, 2024 | Altai Technologies Ltd Altai IX500 Indoor 22 802.11ac Wave 2 AP After login, there are file reads in the background, and... |
| CVE-2024-51398 | MEDIUM | 6.5 | 0.2% | Nov 1, 2024 | Altai Technologies Ltd Altai X500 Indoor 22 802.11ac Wave 2 AP web Management Weak password leakage in the background ma... |
| CVE-2024-51377 | MEDIUM | 5.4 | 0.4% | Nov 1, 2024 | An issue in Ladybird Web Solution Faveo Helpdesk & Servicedesk (On-Premise and Cloud) 9.2.0 allows a remote attacker to ... |
| CVE-2024-40490 | HIGH | 7.5 | 0.5% | Nov 1, 2024 | An issue in Sourcebans++ before v.1.8.0 allows a remote attacker to obtain sensitive information via a crafted XAJAX cal... |
| CVE-2024-28265 | CRITICAL | 9.1 | 0.4% | Nov 1, 2024 | IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php. |
| CVE-2024-22733 | HIGH | 7.5 | 0.6% | Nov 1, 2024 | TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration ... |
| CVE-2024-10662 | HIGH | 8.8 | 1.2% | Nov 1, 2024 | A vulnerability was found in Tenda AC15 15.03.05.19 and classified as critical. This issue affects the function formSetD... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now