2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45414 | CRITICAL | 9.8 | 0.5% | Sep 16, 2024 | The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. ... |
| CVE-2024-44623 | CRITICAL | 9.8 | 1.2% | Sep 16, 2024 | An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.j... |
| CVE-2024-7104 | CRITICAL | 9.8 | 0.5% | Sep 16, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in SFS Consulting ww.Winsure allows Code Injecti... |
| CVE-2024-7098 | CRITICAL | 9.8 | 0.5% | Sep 16, 2024 | Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection. ... |
| CVE-2024-6401 | CRITICAL | 9.8 | 0.4% | Sep 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Ins... |
| CVE-2024-46419 | CRITICAL | 9.8 | 0.7% | Sep 16, 2024 | TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5... |
| CVE-2024-46451 | CRITICAL | 9.8 | 1.2% | Sep 16, 2024 | TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the de... |
| CVE-2024-22399 | CRITICAL | 9.8 | 3.3% | Sep 16, 2024 | Deserialization of Untrusted Data vulnerability in Apache Seata. When developers disable authentication on the Seata-S... |
| CVE-2024-45698 | CRITICAL | 9.8 | 1.1% | Sep 16, 2024 | Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenti... |
| CVE-2024-45697 | CRITICAL | 9.8 | 1.0% | Sep 16, 2024 | Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN p... |
| CVE-2024-45695 | CRITICAL | 9.8 | 1.6% | Sep 16, 2024 | The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which... |
| CVE-2024-45694 | CRITICAL | 9.8 | 1.9% | Sep 16, 2024 | The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which... |
| CVE-2024-46958 | CRITICAL | 9.1 | 0.6% | Sep 16, 2024 | In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may becom... |
| CVE-2024-8880 | CRITICAL | 9.8 | 0.7% | Sep 16, 2024 | A vulnerability classified as critical has been found in playSMS 1.4.4/1.4.5/1.4.6/1.4.7. Affected is an unknown functio... |
| CVE-2024-8875 | CRITICAL | 9.1 | 0.9% | Sep 15, 2024 | A vulnerability classified as critical was found in vedees wcms up to 0.3.2. Affected by this vulnerability is an unknow... |
| CVE-2024-8868 | CRITICAL | 9.8 | 0.9% | Sep 15, 2024 | A vulnerability was found in code-projects Crud Operation System 1.0. It has been rated as critical. This issue affects ... |
| CVE-2024-8862 | CRITICAL | 9.8 | 1.3% | Sep 14, 2024 | A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the functi... |
| CVE-2024-8039 | CRITICAL | 9.8 | 0.4% | Sep 14, 2024 | Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) ca... |
| CVE-2024-44430 | CRITICAL | 9.8 | 0.7% | Sep 13, 2024 | SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary cod... |
| CVE-2024-8782 | CRITICAL | 9.8 | 0.7% | Sep 13, 2024 | A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete ... |
| CVE-2024-46049 | CRITICAL | 9.8 | 0.6% | Sep 13, 2024 | Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function. |
| CVE-2024-46048 | CRITICAL | 9.8 | 10.5% | Sep 13, 2024 | Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i |
| CVE-2024-46046 | CRITICAL | 9.8 | 0.6% | Sep 13, 2024 | Tenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function. |
| CVE-2024-46045 | CRITICAL | 9.8 | 0.6% | Sep 13, 2024 | Tenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function. |
| CVE-2024-46044 | CRITICAL | 9.8 | 0.6% | Sep 13, 2024 | CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now