2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-30597MEDIUM6.5Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security parameter of the formWifiBasicSet func...
CVE-2024-30590MEDIUM6.5Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi functio...
CVE-2024-30588MEDIUM4.3Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi funct...
CVE-2024-30586MEDIUM6.5Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet func...
CVE-2024-30585MEDIUM6.5Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo fu...
CVE-2024-29898MEDIUM6.5CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. An oversight during the writing of the pat...
CVE-2024-29897MEDIUM4.9CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users with (delete) or ...
CVE-2024-29882MEDIUM6.1SRS is a simple, high-efficiency, real-time video server. SRS's `/api/v1/vhosts/vid-<id>?callback=<payload>` endpoint di...
CVE-2024-29200MEDIUM6.5Kimai is a web-based multi-user time-tracking application. The permission `view_other_timesheet` performs differently fo...
CVE-2024-30594MEDIUM6.5Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter functi...
CVE-2024-30422MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor ...
CVE-2024-30421MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a t...
CVE-2024-2818MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 befor...
CVE-2024-29240MEDIUM4.3Missing authorization vulnerability in LayoutSave webapi component in Synology Surveillance Station before 9.2.0-11289 a...
CVE-2024-29239MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Recording.CountByC...
CVE-2024-29238MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log.CountByCategor...
CVE-2024-29237MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in ActionRule.Delete ...
CVE-2024-29236MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in AudioPattern.Delet...
CVE-2024-29235MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in IOModule.EnumLog w...
CVE-2024-29234MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi ...
CVE-2024-29233MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Emap.Delete webapi...
CVE-2024-29232MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Alert.Enum webapi ...
CVE-2024-29231MEDIUM5.4Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station...
CVE-2024-29230MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCa...
CVE-2024-29227MEDIUM5.4Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now