2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7671HIGH7.8A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, may force an Out-of-Bounds Writ...
CVE-2024-7670HIGH7.8A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force an Out-of-Bounds Read. ...
CVE-2024-46503Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-28808LOW2.7An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenti...
CVE-2024-28807MEDIUM6.5An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @C...
CVE-2024-28813HIGH8.4An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management applicatio...
CVE-2024-28812HIGH8.8An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) w...
CVE-2024-28811LOW3.3An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute a...
CVE-2024-28810MEDIUM6.6An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT...
CVE-2024-46635MEDIUM5.9An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access se...
CVE-2024-46511HIGH7.5LoadZilla LLC LoadLogic v1.4.3 was discovered to contain insecure permissions vulnerability which allows a remote attack...
CVE-2024-42017CRITICAL10An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In t...
CVE-2024-35495MEDIUM4.3An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Bu...
CVE-2024-28809HIGH8.8An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update package...
CVE-2024-9158MEDIUM4.6A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local at...
CVE-2024-47536MEDIUM5.4Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo rig...
CVE-2024-46549HIGH7.6An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connecti...
CVE-2024-46548MEDIUM6.3TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eave...
CVE-2024-46540MEDIUM6.3A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attacke...
CVE-2024-45993MEDIUM6.5Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.
CVE-2024-47532MEDIUM6.5RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to prote...
CVE-2024-47531LOW3.5Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass in...
CVE-2024-47530MEDIUM6.1Scout is a web-based visualizer for VCF-files. Open redirect vulnerability allows performing phishing attacks on users b...
CVE-2024-47178MEDIUM5.3basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe...
CVE-2024-47067MEDIUM6.1AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerabil...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now