2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30597 | MEDIUM | 6.5 | 0.5% | Mar 28, 2024 | Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security parameter of the formWifiBasicSet func... |
| CVE-2024-30590 | MEDIUM | 6.5 | 0.5% | Mar 28, 2024 | Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi functio... |
| CVE-2024-30588 | MEDIUM | 4.3 | 0.4% | Mar 28, 2024 | Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi funct... |
| CVE-2024-30586 | MEDIUM | 6.5 | 0.5% | Mar 28, 2024 | Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet func... |
| CVE-2024-30585 | MEDIUM | 6.5 | 0.5% | Mar 28, 2024 | Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo fu... |
| CVE-2024-29898 | MEDIUM | 6.5 | 0.7% | Mar 28, 2024 | CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. An oversight during the writing of the pat... |
| CVE-2024-29897 | MEDIUM | 4.9 | 0.7% | Mar 28, 2024 | CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users with (delete) or ... |
| CVE-2024-29882 | MEDIUM | 6.1 | 1.1% | Mar 28, 2024 | SRS is a simple, high-efficiency, real-time video server. SRS's `/api/v1/vhosts/vid-<id>?callback=<payload>` endpoint di... |
| CVE-2024-29200 | MEDIUM | 6.5 | 0.6% | Mar 28, 2024 | Kimai is a web-based multi-user time-tracking application. The permission `view_other_timesheet` performs differently fo... |
| CVE-2024-30594 | MEDIUM | 6.5 | 0.5% | Mar 28, 2024 | Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter functi... |
| CVE-2024-30422 | MEDIUM | 5.4 | 0.3% | Mar 28, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor ... |
| CVE-2024-30421 | MEDIUM | 4.3 | 0.2% | Mar 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a t... |
| CVE-2024-2818 | MEDIUM | 6.5 | 0.9% | Mar 28, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 befor... |
| CVE-2024-29240 | MEDIUM | 4.3 | 0.7% | Mar 28, 2024 | Missing authorization vulnerability in LayoutSave webapi component in Synology Surveillance Station before 9.2.0-11289 a... |
| CVE-2024-29239 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Recording.CountByC... |
| CVE-2024-29238 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log.CountByCategor... |
| CVE-2024-29237 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in ActionRule.Delete ... |
| CVE-2024-29236 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in AudioPattern.Delet... |
| CVE-2024-29235 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in IOModule.EnumLog w... |
| CVE-2024-29234 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi ... |
| CVE-2024-29233 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Emap.Delete webapi... |
| CVE-2024-29232 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Alert.Enum webapi ... |
| CVE-2024-29231 | MEDIUM | 5.4 | 0.7% | Mar 28, 2024 | Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station... |
| CVE-2024-29230 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCa... |
| CVE-2024-29227 | MEDIUM | 5.4 | 0.6% | Mar 28, 2024 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now