2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-40864LOW2.7The issue was addressed with improved handling of protocols. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequ...
CVE-2024-54809CRITICAL9.8Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header fu...
CVE-2024-54808CRITICAL9.8Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionSe...
CVE-2024-54807CRITICAL9.8In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exe...
CVE-2024-54806CRITICAL9.8Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execu...
CVE-2024-54805CRITICAL9.8Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque...
CVE-2024-54804CRITICAL9.8Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque...
CVE-2024-54803CRITICAL9.8Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque...
CVE-2024-54802CRITICAL9.8In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow...
CVE-2024-24456MEDIUM5.9An E-RAB Release Command packet containing a malformed NAS PDU will cause the Athonet MME to immediately crash, potentia...
CVE-2024-12021HIGH8.5Coverity versions prior to 2024.9.0 are vulnerable to stored cross-site scripting (XSS) in various administrative interf...
CVE-2024-55093MEDIUM4.7phpIPAM through 1.7.3 has a reflected Cross-Site Scripting (XSS) vulnerability in the install scripts.
CVE-2024-13804CRITICAL9.8Unauthenticated RCE in HPE Insight Cluster Management Utility
CVE-2024-55895MEDIUM5.3IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec...
CVE-2024-11180MEDIUM5.4The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Tim...
CVE-2024-13557MEDIUM6.5The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t...
CVE-2024-7577HIGH7.5IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation ...
CVE-2024-51477MEDIUM6.5IBM InfoSphere Information Server 11.7 could allow an authenticated to obtain sensitive username information due to an...
CVE-2024-43186MEDIUM6.5IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored ...
CVE-2024-58130MEDIUM6.1In app/Controller/Component/RestResponseComponent.php in MISP before 2.4.193, REST endpoints have a lack of sanitization...
CVE-2024-58129MEDIUM4.8In MISP before 2.4.193, menu_custom_right_link_html parameters can be set via the UI (i.e., without using the CLI) and t...
CVE-2024-58128MEDIUM4.8In MISP before 2.4.193, menu_custom_right_link parameters can be set via the UI (i.e., without using the CLI) and thus a...
CVE-2024-23338Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-53427. Reason: This candidate is a ...
CVE-2024-6875MEDIUM6.5A vulnerability was found in the Infinispan component in Red Hat Data Grid. The REST compare API may have a buffer leak ...
CVE-2024-57083HIGH7.5A prototype pollution in the component Module.mergeObjects (redoc/bundles/redoc.lib.js:2) of redoc <= 2.2.0 allows attac...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now