2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-29995HIGH8.1Windows Kerberos Elevation of Privilege Vulnerability
CVE-2024-7113HIGH8.7If exploited, this vulnerability could cause a SuiteLink server to consume excessive system resources and slow down proc...
CVE-2024-6619HIGH8.5In Ocean Data Systems Dream Report, an incorrect permission vulnerability could allow a local unprivileged attacker to e...
CVE-2024-6618HIGH8.5In Ocean Data Systems Dream Report, a path traversal vulnerability could allow an attacker to perform remote code execut...
CVE-2024-41711MEDIUM6.8A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, ...
CVE-2024-41614MEDIUM4.8symphonycms <=2.7.10 is vulnerable to Cross Site Scripting (XSS) in the Comment component for articles.
CVE-2024-41613MEDIUM5.4A Cross Site Scripting (XSS) vulnerability in Symphony CMS 2.7.10 allows remote attackers to inject arbitrary web script...
CVE-2024-37015HIGH7.4An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/T...
CVE-2024-36446HIGH8.8The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to cond...
CVE-2024-21981MEDIUM5.7Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrar...
CVE-2024-7746CRITICAL9.8Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Auth...
CVE-2024-36505MEDIUM5.5An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7...
CVE-2024-21757HIGH7.8A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and v...
CVE-2024-6384MEDIUM5.3"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifi...
CVE-2024-6788CRITICAL9.8A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the pa...
CVE-2024-42740MEDIUM6.8In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability...
CVE-2024-42739HIGH8.8In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability...
CVE-2024-42738HIGH8.8In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability...
CVE-2024-42737HIGH8.8In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability...
CVE-2024-42736HIGH7.8In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability...
CVE-2024-41623CRITICAL9.8An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code ...
CVE-2024-5849HIGH7.1An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the...
CVE-2024-3913MEDIUM5.9An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable...
CVE-2024-38502HIGH7.1An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affe...
CVE-2024-38501MEDIUM6.1An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML c...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now