2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-10279 | CRITICAL | 9.8 | 0.6% | Oct 23, 2024 | A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. This vulnerability affects unknown code o... |
| CVE-2024-10278 | CRITICAL | 9.8 | 0.6% | Oct 23, 2024 | A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. This affects an unknown part of the fil... |
| CVE-2024-10277 | CRITICAL | 9.8 | 0.6% | Oct 23, 2024 | A vulnerability was found in ESAFENET CDG 5 and classified as critical. Affected by this issue is some unknown functiona... |
| CVE-2024-43924 | CRITICAL | 9.8 | 0.5% | Oct 23, 2024 | Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrai... |
| CVE-2024-9947 | CRITICAL | 9.8 | 0.5% | Oct 23, 2024 | The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4... |
| CVE-2024-46483 | CRITICAL | 9.8 | 1.1% | Oct 22, 2024 | Xlight FTP Server <3.9.4.3 has an integer overflow vulnerability in the packet parsing logic of the SFTP server, which c... |
| CVE-2024-44812 | CRITICAL | 9.8 | 1.2% | Oct 22, 2024 | SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the usern... |
| CVE-2024-43698 | CRITICAL | 9.8 | 0.4% | Oct 22, 2024 | Kieback & Peter's DDC4000 series uses weak credentials, which may allow an unauthenticated attacker to get full admin ri... |
| CVE-2024-41717 | CRITICAL | 9.8 | 0.6% | Oct 22, 2024 | Kieback & Peter's DDC4000 series is vulnerable to a path traversal vulnerability, which may allow an unauthenticated att... |
| CVE-2024-40494 | CRITICAL | 9.8 | 1.1% | Oct 22, 2024 | Buffer Overflow in coap_msg.c in FreeCoAP allows remote attackers to execute arbitrary code or cause a denial of service... |
| CVE-2024-40493 | CRITICAL | 9.8 | 0.8% | Oct 22, 2024 | Null Pointer Dereference in `coap_client_exchange_blockwise2` function in Keith Cullen FreeCoAP 1.0 allows remote attack... |
| CVE-2024-26519 | CRITICAL | 9 | 0.3% | Oct 22, 2024 | An issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a cr... |
| CVE-2024-48919 | CRITICAL | 9.2 | 0.5% | Oct 22, 2024 | Cursor is a code editor built for programming with AI. Prior to Sep 27, 2024, if a user generated a terminal command via... |
| CVE-2024-48904 | CRITICAL | 9.8 | 2.5% | Oct 22, 2024 | An command injection vulnerability in Trend Micro Cloud Edge could allow a remote attacker to execute arbitrary code on ... |
| CVE-2024-46902 | CRITICAL | 9.1 | 1.9% | Oct 22, 2024 | A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose... |
| CVE-2024-9129 | CRITICAL | 9.3 | 0.4% | Oct 22, 2024 | In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered. Reported by Dylan Ma... |
| CVE-2024-43177 | CRITICAL | 9.8 | 0.3% | Oct 22, 2024 | IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute. |
| CVE-2024-41713 | CRITICAL | 9.1 | 98.1% | Oct 21, 2024 | A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could... |
| CVE-2024-40089 | CRITICAL | 9.1 | 1.4% | Oct 21, 2024 | A Command Injection vulnerability in Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, authenticated attackers to exec... |
| CVE-2024-40087 | CRITICAL | 9.6 | 0.4% | Oct 21, 2024 | Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Insecure Permissions. Lack of authentication in the custom TCP ser... |
| CVE-2024-40086 | CRITICAL | 9.6 | 0.7% | Oct 21, 2024 | A Buffer Overflow vulnerability in the local_app_set_router_wifi_SSID_PWD function of Vilo 5 Mesh WiFi System <= 5.16.1.... |
| CVE-2024-40085 | CRITICAL | 9.6 | 0.7% | Oct 21, 2024 | A Buffer Overflow vulnerability in the local_app_set_router_wan function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows ... |
| CVE-2024-40084 | CRITICAL | 9.6 | 0.7% | Oct 21, 2024 | A Buffer Overflow in the Boa webserver of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers ... |
| CVE-2024-40083 | CRITICAL | 9.6 | 0.5% | Oct 21, 2024 | A Buffer Overflow vulnerabilty in the local_app_set_router_token function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows... |
| CVE-2024-35314 | CRITICAL | 9.8 | 1.7% | Oct 21, 2024 | A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instanc... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now