2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22545 | HIGH | 7.8 | 0.5% | Jan 26, 2024 | An issue was discovered in TRENDnet TEW-824DRU version 1.04b01, allows unauthenticated attackers to execute arbitrary co... |
| CVE-2024-21385 | HIGH | 8.3 | 1.0% | Jan 26, 2024 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2024-23630 | HIGH | 8.8 | 1.5% | Jan 26, 2024 | An arbitrary firmware upload vulnerability exists in the Motorola MR2600. An attacker can exploit this vulnerability to... |
| CVE-2024-23629 | HIGH | 7.5 | 1.1% | Jan 26, 2024 | An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this ... |
| CVE-2024-23628 | HIGH | 8.8 | 3.2% | Jan 26, 2024 | A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote ... |
| CVE-2024-23627 | HIGH | 8.8 | 3.5% | Jan 26, 2024 | A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote a... |
| CVE-2024-23626 | HIGH | 8.8 | 3.5% | Jan 26, 2024 | A command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker ... |
| CVE-2024-23620 | HIGH | 7.8 | 0.2% | Jan 26, 2024 | An improper privilege management vulnerability exists in IBM Merge Healthcare eFilm Workstation. A local, authenticated ... |
| CVE-2024-23617 | HIGH | 8.8 | 1.7% | Jan 26, 2024 | A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before. A remote, unauthentic... |
| CVE-2024-21619 | HIGH | 7.5 | 0.9% | Jan 25, 2024 | A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sens... |
| CVE-2024-0889 | HIGH | 7.5 | 1.4% | Jan 25, 2024 | A vulnerability was found in Kmint21 Golden FTP Server 2.02b and classified as problematic. This issue affects some unkn... |
| CVE-2024-0888 | HIGH | 7.5 | 1.1% | Jan 25, 2024 | A vulnerability, which was classified as problematic, was found in BORGChat 1.0.0 Build 438. This affects an unknown par... |
| CVE-2024-0887 | HIGH | 7.5 | 1.1% | Jan 25, 2024 | A vulnerability, which was classified as problematic, has been found in Mafiatic Blue Server 1.1. Affected by this issue... |
| CVE-2024-24399 | HIGH | 7.2 | 15.6% | Jan 25, 2024 | An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by ... |
| CVE-2024-22636 | HIGH | 8.8 | 1.3% | Jan 25, 2024 | PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. Th... |
| CVE-2024-0885 | HIGH | 7.5 | 1.4% | Jan 25, 2024 | A vulnerability classified as problematic has been found in SpyCamLizard 1.230. Affected is an unknown function of the c... |
| CVE-2024-23656 | HIGH | 7.5 | 0.4% | Jan 25, 2024 | Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with... |
| CVE-2024-0882 | HIGH | 7.5 | 0.8% | Jan 25, 2024 | A vulnerability was found in qwdigital LinkWechat 5.1.0. It has been classified as problematic. This affects an unknown ... |
| CVE-2024-0880 | HIGH | 8.8 | 0.4% | Jan 25, 2024 | A vulnerability was found in Qidianbang qdbcrm 1.1.0 and classified as problematic. Affected by this issue is some unkno... |
| CVE-2024-22749 | HIGH | 7.8 | 0.5% | Jan 25, 2024 | GPAC v2.3 was detected to contain a buffer overflow via the function gf_isom_new_generic_sample_description function in ... |
| CVE-2024-0822 | HIGH | 7.5 | 0.7% | Jan 25, 2024 | An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system w... |
| CVE-2024-23307 | HIGH | 7.8 | 0.6% | Jan 25, 2024 | Integer Overflow or Wraparound vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (md, raid, raid5 modules) a... |
| CVE-2024-23985 | HIGH | 7.5 | 3.6% | Jan 25, 2024 | EzServer 6.4.017 allows a denial of service (daemon crash) via a long string, such as one for the RNTO command. |
| CVE-2024-23646 | HIGH | 8.8 | 0.8% | Jan 24, 2024 | Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The application allows users to create zip... |
| CVE-2024-23644 | HIGH | 8.1 | 0.6% | Jan 24, 2024 | Trillium is a composable toolkit for building internet applications with async rust. In `trillium-http` prior to 0.3.12 ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now