2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-48647HIGH7.2A file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbit...
CVE-2024-48646HIGH8.1An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files with...
CVE-2024-48569MEDIUM5.4Proactive Risk Manager version 9.1.1.0 is affected by multiple Cross-Site Scripting (XSS) vulnerabilities in the add/edi...
CVE-2024-48241MEDIUM5.5An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function...
CVE-2024-48214HIGH8.4KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local netw...
CVE-2024-42041HIGH8.1The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 f...
CVE-2024-37573HIGH8.4The Talkatone com.talkatone.android application 8.4.6 for Android enables any installed application (with no permissions...
CVE-2024-36060HIGH8.8EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping ...
CVE-2024-31975MEDIUM4.8EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID para...
CVE-2024-31973MEDIUM5.2Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS...
CVE-2024-31972MEDIUM4.3EnGenius ESR580 A8J-EMR5000 devices allow a remote attacker to conduct stored XSS attacks that could lead to arbitrary J...
CVE-2024-10456CRITICAL9.8Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that...
CVE-2024-9110MEDIUM6.1A medium severity vulnerability has been identified within Privileged Identity which can allow an attacker to perform re...
CVE-2024-51258HIGH8.8DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm...
CVE-2024-50344MEDIUM4.6I, Librarian is an open-source version of a PDF managing SaaS. Supplemental Files are allowed to be viewed in the browse...
CVE-2024-50419CRITICAL9.8Incorrect Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploitin...
CVE-2024-51301HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51300HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51299HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51298CRITICAL9.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51296HIGH8.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51257HIGH8.8DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm...
CVE-2024-50353MEDIUM5.3ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files ...
CVE-2024-33700HIGH7.5The LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP functionalit...
CVE-2024-33699HIGH8.8The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now