2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48647 | HIGH | 7.2 | 0.8% | Oct 30, 2024 | A file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbit... |
| CVE-2024-48646 | HIGH | 8.1 | 0.5% | Oct 30, 2024 | An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files with... |
| CVE-2024-48569 | MEDIUM | 5.4 | 0.5% | Oct 30, 2024 | Proactive Risk Manager version 9.1.1.0 is affected by multiple Cross-Site Scripting (XSS) vulnerabilities in the add/edi... |
| CVE-2024-48241 | MEDIUM | 5.5 | 0.2% | Oct 30, 2024 | An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function... |
| CVE-2024-48214 | HIGH | 8.4 | 1.0% | Oct 30, 2024 | KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local netw... |
| CVE-2024-42041 | HIGH | 8.1 | 0.3% | Oct 30, 2024 | The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 f... |
| CVE-2024-37573 | HIGH | 8.4 | 0.2% | Oct 30, 2024 | The Talkatone com.talkatone.android application 8.4.6 for Android enables any installed application (with no permissions... |
| CVE-2024-36060 | HIGH | 8.8 | 1.4% | Oct 30, 2024 | EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping ... |
| CVE-2024-31975 | MEDIUM | 4.8 | 0.3% | Oct 30, 2024 | EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID para... |
| CVE-2024-31973 | MEDIUM | 5.2 | 0.5% | Oct 30, 2024 | Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS... |
| CVE-2024-31972 | MEDIUM | 4.3 | 0.4% | Oct 30, 2024 | EnGenius ESR580 A8J-EMR5000 devices allow a remote attacker to conduct stored XSS attacks that could lead to arbitrary J... |
| CVE-2024-10456 | CRITICAL | 9.8 | 17.7% | Oct 30, 2024 | Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that... |
| CVE-2024-9110 | MEDIUM | 6.1 | 0.2% | Oct 30, 2024 | A medium severity vulnerability has been identified within Privileged Identity which can allow an attacker to perform re... |
| CVE-2024-51258 | HIGH | 8.8 | 0.5% | Oct 30, 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm... |
| CVE-2024-50344 | MEDIUM | 4.6 | 0.3% | Oct 30, 2024 | I, Librarian is an open-source version of a PDF managing SaaS. Supplemental Files are allowed to be viewed in the browse... |
| CVE-2024-50419 | CRITICAL | 9.8 | 0.3% | Oct 30, 2024 | Incorrect Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploitin... |
| CVE-2024-51301 | HIGH | 8.8 | 0.6% | Oct 30, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51300 | HIGH | 8.8 | 0.6% | Oct 30, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51299 | HIGH | 8.8 | 0.6% | Oct 30, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51298 | CRITICAL | 9.8 | 0.6% | Oct 30, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51296 | HIGH | 8.8 | 0.6% | Oct 30, 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman... |
| CVE-2024-51257 | HIGH | 8.8 | 0.4% | Oct 30, 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm... |
| CVE-2024-50353 | MEDIUM | 5.3 | 0.3% | Oct 30, 2024 | ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files ... |
| CVE-2024-33700 | HIGH | 7.5 | 0.8% | Oct 30, 2024 | The LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP functionalit... |
| CVE-2024-33699 | HIGH | 8.8 | 9.2% | Oct 30, 2024 | The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now