2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-58355CRITICAL9.3Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking...
CVE-2024-58354CRITICAL9.9cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Acti...
CVE-2024-58353CRITICAL9.3Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS) on the publicly ac...
CVE-2024-51315CRITICAL9.8The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/Se...
CVE-2024-51314CRITICAL9.8The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/se...
CVE-2024-51312CRITICAL9.8The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/Se...
CVE-2024-51313CRITICAL9.8The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/Se...
CVE-2024-51311CRITICAL9.8The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/Se...
CVE-2024-58366CRITICAL9SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when script...
CVE-2024-23564CRITICAL9.1HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obta...
CVE-2024-14037CRITICAL9.8Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote...
CVE-2024-58351CRITICAL9.8Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig opti...
CVE-2024-52488CRITICAL9.9Subscriber Arbitrary File Upload in Grip <= 1.0.9 versions.
CVE-2024-58349CRITICAL9.8WordPress Theme Travelscape 1.0.3 contains an arbitrary file upload vulnerability that allows unauthenticated attackers ...
CVE-2024-58348CRITICAL9.8WordPress Background Image Cropper version 1.2 contains a remote code execution vulnerability that allows unauthenticate...
CVE-2024-27892CRITICAL9.6Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been...
CVE-2024-27890CRITICAL9.6Affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been...
CVE-2024-40684CRITICAL9.8IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,...
CVE-2024-51092CRITICAL9.1LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutContr...
CVE-2024-46636CRITICAL9.4NASA Earth Observing System Data and Information System (EOSDIS) MODAPS v8.1 was discovered to contain a SQL injection v...
CVE-2024-2374CRITICAL9.1The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the ...
CVE-2024-36058CRITICAL9.8The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fail...
CVE-2024-36057CRITICAL9.8Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code ex...
CVE-2024-14034CRITICAL9.8Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) managem...
CVE-2024-43028CRITICAL9.8A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to exe...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now