2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41592HIGH8DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because Ge...
CVE-2024-41591MEDIUM6.1DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.
CVE-2024-41590HIGH8Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on ...
CVE-2024-41589HIGH8.8DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.
CVE-2024-41588HIGH8The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflo...
CVE-2024-41587MEDIUM5.4Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor31...
CVE-2024-41586HIGH8A stack-based Buffer Overflow vulnerability in DrayTek Vigor310 devices through 4.3.2.6 allows a remote attacker to exec...
CVE-2024-41585MEDIUM6.8DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker ...
CVE-2024-41584MEDIUM4.7DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing vali...
CVE-2024-41583MEDIUM4.7DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to stored Cross Site Scripting (XSS) by authenticated users due...
CVE-2024-47762MEDIUM5.8Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment v...
CVE-2024-41988CRITICAL9.3TEM Opera Plus FM Family Transmitter allows access to an unprotected endpoint that allows MPFS File System binary image ...
CVE-2024-41987HIGH8.6The TEM Opera Plus FM Family Transmitter application interface allows users to perform certain actions via HTTP requests...
CVE-2024-34535MEDIUM5.9In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.
CVE-2024-8508MEDIUM5.3NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRs...
CVE-2024-7826CRITICAL9.8Improper Check for Unusual or Exceptional Conditions vulnerability in Webroot SecureAnywhere - Web Shield on Windows, AR...
CVE-2024-7825CRITICAL9.8Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Wi...
CVE-2024-7824CRITICAL9.8Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Wi...
CVE-2024-45872MEDIUM6.3Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient...
CVE-2024-45871MEDIUM6.3Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS).
CVE-2024-0125LOW3.3NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can ca...
CVE-2024-0124LOW3.3NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can ca...
CVE-2024-0123LOW3.3NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker m...
CVE-2024-45870MEDIUM6.5Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file.
CVE-2024-42415HIGH7.8An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Pro...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now