2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-48150CRITICAL9.8D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.
CVE-2024-41997MEDIUM6.6An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulne...
CVE-2024-9823HIGH7.5There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote ...
CVE-2024-48261Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-48251. Reason: This candidate is a reservation d...
CVE-2024-48259HIGH7.3Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.
CVE-2024-48257CRITICAL9.8Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.
CVE-2024-48251CRITICAL9.8Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.
CVE-2024-48249HIGH7.3Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.
CVE-2024-40616Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-9936MEDIUM6.5When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially lea...
CVE-2024-8602MEDIUM6.3When the XML is read from the codes in the PDF and parsed using a DocumentBuilder, the default settings of the DocumentB...
CVE-2024-7847HIGH7.8VULNERABILITY DETAILS Rockwell Automation used the latest versions of the CVSS scoring system to assess the following v...
CVE-2024-48255CRITICAL9.8Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.
CVE-2024-48253CRITICAL9.8Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.
CVE-2024-48120MEDIUM5.4X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject ma...
CVE-2024-48119MEDIUM5.4Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary H...
CVE-2024-9139HIGH8.6The affected product permits OS command injection through improperly restricted commands, potentially allowing attackers...
CVE-2024-9137CRITICAL9.4The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulner...
CVE-2024-46911MEDIUM4.7Cross-site Resource Forgery (CSRF), Privilege escalation vulnerability in Apache Roller. On multi-blog/user Roller websi...
CVE-2024-43701HIGH7.8Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory...
CVE-2024-38863HIGH7.5Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35...
CVE-2024-38862MEDIUM4.4Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35, <2.1.0p48 and ...
CVE-2024-9924CRITICAL9.8The fix for CVE-2024-26261 was incomplete, and and the specific package for OAKlouds from Hgiga remains at risk. Unauthe...
CVE-2024-9923MEDIUM4.9The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with ...
CVE-2024-49214MEDIUM5.3QUIC in HAProxy 3.1.x before 3.1-dev7, 3.0.x before 3.0.5, and 2.9.x before 2.9.11 allows opening a 0-RTT session with a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now