2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-45414CRITICAL9.8The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. ...
CVE-2024-44623CRITICAL9.8An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.j...
CVE-2024-7104CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in SFS Consulting ww.Winsure allows Code Injecti...
CVE-2024-7098CRITICAL9.8Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection. ...
CVE-2024-6401CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Ins...
CVE-2024-46419CRITICAL9.8TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5...
CVE-2024-46451CRITICAL9.8TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the de...
CVE-2024-22399CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache Seata.  When developers disable authentication on the Seata-S...
CVE-2024-45698CRITICAL9.8Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenti...
CVE-2024-45697CRITICAL9.8Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN p...
CVE-2024-45695CRITICAL9.8The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which...
CVE-2024-45694CRITICAL9.8The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which...
CVE-2024-46958CRITICAL9.1In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may becom...
CVE-2024-8880CRITICAL9.8A vulnerability classified as critical has been found in playSMS 1.4.4/1.4.5/1.4.6/1.4.7. Affected is an unknown functio...
CVE-2024-8875CRITICAL9.1A vulnerability classified as critical was found in vedees wcms up to 0.3.2. Affected by this vulnerability is an unknow...
CVE-2024-8868CRITICAL9.8A vulnerability was found in code-projects Crud Operation System 1.0. It has been rated as critical. This issue affects ...
CVE-2024-8862CRITICAL9.8A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the functi...
CVE-2024-8039CRITICAL9.8Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) ca...
CVE-2024-44430CRITICAL9.8SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary cod...
CVE-2024-8782CRITICAL9.8A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete ...
CVE-2024-46049CRITICAL9.8Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.
CVE-2024-46048CRITICAL9.8Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i
CVE-2024-46046CRITICAL9.8Tenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.
CVE-2024-46045CRITICAL9.8Tenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function.
CVE-2024-46044CRITICAL9.8CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now