2024 CVE Vulnerabilities
39,239 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-42061 | MEDIUM | 6.1 | 0.3% | Sep 3, 2024 | A reflected cross-site scripting (XSS) vulnerability in the CGI program "dynamic_script.cgi" of Zyxel ATP series firmwar... |
| CVE-2024-7203 | HIGH | 7.2 | 1.3% | Sep 3, 2024 | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and... |
| CVE-2024-6343 | MEDIUM | 4.9 | 0.6% | Sep 3, 2024 | A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG F... |
| CVE-2024-5412 | HIGH | 7.5 | 0.7% | Sep 3, 2024 | A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 cou... |
| CVE-2024-42060 | HIGH | 7.2 | 1.3% | Sep 3, 2024 | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, US... |
| CVE-2024-42059 | HIGH | 7.2 | 1.3% | Sep 3, 2024 | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, US... |
| CVE-2024-42058 | HIGH | 7.5 | 0.6% | Sep 3, 2024 | A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series... |
| CVE-2024-42057 | HIGH | 8.1 | 1.3% | Sep 3, 2024 | A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.3... |
| CVE-2024-8380 | CRITICAL | 9.8 | 0.6% | Sep 3, 2024 | A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been rated as critical. This ... |
| CVE-2024-45623 | CRITICAL | 9.8 | 0.9% | Sep 2, 2024 | D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer... |
| CVE-2024-1621 | HIGH | 7.5 | 0.4% | Sep 2, 2024 | The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compr... |
| CVE-2024-45622 | CRITICAL | 9.8 | 36.0% | Sep 2, 2024 | ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for A... |
| CVE-2024-45621 | MEDIUM | 5.4 | 0.3% | Sep 2, 2024 | The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related t... |
| CVE-2024-6921 | HIGH | 7.5 | 0.2% | Sep 2, 2024 | Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retriev... |
| CVE-2024-6920 | MEDIUM | 6.1 | 0.2% | Sep 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NAC Telecommunicat... |
| CVE-2024-6919 | CRITICAL | 9.8 | 0.4% | Sep 2, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NAC Telecommunicat... |
| CVE-2024-45388 | HIGH | 7.5 | 55.9% | Sep 2, 2024 | Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/ap... |
| CVE-2024-45313 | MEDIUM | 5.4 | 0.3% | Sep 2, 2024 | Overleaf is a web-based collaborative LaTeX editor. When installing Server Pro using the Overleaf Toolkit from before 20... |
| CVE-2024-45312 | MEDIUM | 5.3 | 0.5% | Sep 2, 2024 | Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or... |
| CVE-2024-45311 | HIGH | 7.5 | 0.6% | Sep 2, 2024 | Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. As of quinn-proto 0.11, it is... |
| CVE-2024-45308 | MEDIUM | 6.5 | 0.6% | Sep 2, 2024 | HedgeDoc is an open source, real-time, collaborative, markdown notes application. When using HedgeDoc 1 with MySQL or Ma... |
| CVE-2024-45306 | MEDIUM | 5.5 | 0.3% | Sep 2, 2024 | Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and rem... |
| CVE-2024-45305 | LOW | 2.5 | 0.2% | Sep 2, 2024 | gix-path is a crate of the gitoxide project dealing with git paths and their conversions. `gix-path` executes `git` to f... |
| CVE-2024-44947 | MEDIUM | 5.5 | 0.9% | Sep 2, 2024 | In the Linux kernel, the following vulnerability has been resolved: fuse: Initialize beyond-EOF page contents before se... |
| CVE-2024-43801 | MEDIUM | 5.4 | 0.3% | Sep 2, 2024 | Jellyfin is an open source self hosted media server. The Jellyfin user profile image upload accepts SVG files, allowing ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now