2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-42061MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the CGI program "dynamic_script.cgi" of Zyxel ATP series firmwar...
CVE-2024-7203HIGH7.2A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and...
CVE-2024-6343MEDIUM4.9A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG F...
CVE-2024-5412HIGH7.5A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 cou...
CVE-2024-42060HIGH7.2A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, US...
CVE-2024-42059HIGH7.2A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, US...
CVE-2024-42058HIGH7.5A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series...
CVE-2024-42057HIGH8.1A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.3...
CVE-2024-8380CRITICAL9.8A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been rated as critical. This ...
CVE-2024-45623CRITICAL9.8D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer...
CVE-2024-1621HIGH7.5The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compr...
CVE-2024-45622CRITICAL9.8ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for A...
CVE-2024-45621MEDIUM5.4The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related t...
CVE-2024-6921HIGH7.5Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retriev...
CVE-2024-6920MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NAC Telecommunicat...
CVE-2024-6919CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NAC Telecommunicat...
CVE-2024-45388HIGH7.5Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/ap...
CVE-2024-45313MEDIUM5.4Overleaf is a web-based collaborative LaTeX editor. When installing Server Pro using the Overleaf Toolkit from before 20...
CVE-2024-45312MEDIUM5.3Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or...
CVE-2024-45311HIGH7.5Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. As of quinn-proto 0.11, it is...
CVE-2024-45308MEDIUM6.5HedgeDoc is an open source, real-time, collaborative, markdown notes application. When using HedgeDoc 1 with MySQL or Ma...
CVE-2024-45306MEDIUM5.5Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and rem...
CVE-2024-45305LOW2.5gix-path is a crate of the gitoxide project dealing with git paths and their conversions. `gix-path` executes `git` to f...
CVE-2024-44947MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fuse: Initialize beyond-EOF page contents before se...
CVE-2024-43801MEDIUM5.4Jellyfin is an open source self hosted media server. The Jellyfin user profile image upload accepts SVG files, allowing ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now