2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41592 | HIGH | 8 | 1.4% | Oct 3, 2024 | DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because Ge... |
| CVE-2024-41591 | MEDIUM | 6.1 | 0.2% | Oct 3, 2024 | DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS. |
| CVE-2024-41590 | HIGH | 8 | 0.3% | Oct 3, 2024 | Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on ... |
| CVE-2024-41589 | HIGH | 8.8 | 0.3% | Oct 3, 2024 | DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests. |
| CVE-2024-41588 | HIGH | 8 | 0.3% | Oct 3, 2024 | The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflo... |
| CVE-2024-41587 | MEDIUM | 5.4 | 0.2% | Oct 3, 2024 | Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor31... |
| CVE-2024-41586 | HIGH | 8 | 0.5% | Oct 3, 2024 | A stack-based Buffer Overflow vulnerability in DrayTek Vigor310 devices through 4.3.2.6 allows a remote attacker to exec... |
| CVE-2024-41585 | MEDIUM | 6.8 | 0.8% | Oct 3, 2024 | DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker ... |
| CVE-2024-41584 | MEDIUM | 4.7 | 0.3% | Oct 3, 2024 | DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing vali... |
| CVE-2024-41583 | MEDIUM | 4.7 | 0.3% | Oct 3, 2024 | DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to stored Cross Site Scripting (XSS) by authenticated users due... |
| CVE-2024-47762 | MEDIUM | 5.8 | 0.4% | Oct 3, 2024 | Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment v... |
| CVE-2024-41988 | CRITICAL | 9.3 | 0.6% | Oct 3, 2024 | TEM Opera Plus FM Family Transmitter allows access to an unprotected endpoint that allows MPFS File System binary image ... |
| CVE-2024-41987 | HIGH | 8.6 | 0.2% | Oct 3, 2024 | The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests... |
| CVE-2024-34535 | MEDIUM | 5.9 | 0.4% | Oct 3, 2024 | In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header. |
| CVE-2024-8508 | MEDIUM | 5.3 | 0.8% | Oct 3, 2024 | NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRs... |
| CVE-2024-7826 | CRITICAL | 9.8 | 0.4% | Oct 3, 2024 | Improper Check for Unusual or Exceptional Conditions vulnerability in Webroot SecureAnywhere - Web Shield on Windows, AR... |
| CVE-2024-7825 | CRITICAL | 9.8 | 0.4% | Oct 3, 2024 | Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Wi... |
| CVE-2024-7824 | CRITICAL | 9.8 | 0.4% | Oct 3, 2024 | Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Wi... |
| CVE-2024-45872 | MEDIUM | 6.3 | 0.4% | Oct 3, 2024 | Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient... |
| CVE-2024-45871 | MEDIUM | 6.3 | 0.4% | Oct 3, 2024 | Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS). |
| CVE-2024-0125 | LOW | 3.3 | 0.2% | Oct 3, 2024 | NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can ca... |
| CVE-2024-0124 | LOW | 3.3 | 0.2% | Oct 3, 2024 | NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can ca... |
| CVE-2024-0123 | LOW | 3.3 | 0.2% | Oct 3, 2024 | NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker m... |
| CVE-2024-45870 | MEDIUM | 6.5 | 0.4% | Oct 3, 2024 | Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file. |
| CVE-2024-42415 | HIGH | 7.8 | 0.5% | Oct 3, 2024 | An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Pro... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now