2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-27729MEDIUM6.1Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via t...
CVE-2024-27728MEDIUM6.1Cross Site Scripting vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information via t...
CVE-2024-25633MEDIUM5.4eLabFTW is an open source electronic lab notebook for research labs. In an eLabFTW system, one can configure who is allo...
CVE-2024-23168CRITICAL9.8Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSoc...
CVE-2024-32231MEDIUM6.3Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.
CVE-2024-22219MEDIUM6.3XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows...
CVE-2024-22218HIGH8.8XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows...
CVE-2024-22217MEDIUM6.5A Server-Side Request Forgery (SSRF) vulnerability in Terminalfour before 8.3.19 allows authenticated users to use speci...
CVE-2024-42987HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack-based buffer overflow vulnerability in the fromPptpUserAdd f...
CVE-2024-42986HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the PPPOEPassword parameter in the fromAdvSetWa...
CVE-2024-42985HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromNatlimit function...
CVE-2024-42984HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromP2pListFilter fun...
CVE-2024-42983HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the pptpPPW parameter in the fromAdvSetWan func...
CVE-2024-42982HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer functi...
CVE-2024-42981HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the delno parameter in the fromPptpUserSetting ...
CVE-2024-42980HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ImForm function....
CVE-2024-42979HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the frmL7ProtForm functio...
CVE-2024-42978CRITICAL9.8An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary co...
CVE-2024-42977HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the qos parameter in the fromqossetting functio...
CVE-2024-42976HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeClientFilter ...
CVE-2024-42974HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromwebExcptypemanFil...
CVE-2024-42973HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSetlpBind functio...
CVE-2024-42969HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSafeUrlFilter fun...
CVE-2024-42968HIGH7.5Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the Go parameter in the fromSafeUrlFilter funct...
CVE-2024-42967CRITICAL9.8Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration fil...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now