2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-42470CRITICAL9.1openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. S...
CVE-2024-42469CRITICAL9.8openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. P...
CVE-2024-42467CRITICAL10openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. I...
CVE-2024-42001CRITICAL9.8An improper authentication vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeate...
CVE-2024-41577CRITICAL9.8An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arb...
CVE-2024-41570CRITICAL9.8An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send...
CVE-2024-41476CRITICAL9.8AMTT Hotel Broadband Operation System (HiBOS) V3.0.3.151204 and before is vulnerable to SQL Injection via /manager/card/...
CVE-2024-40486CRITICAL9.8A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execut...
CVE-2024-40482CRITICAL9.8An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System...
CVE-2024-40480CRITICAL9.8A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam S...
CVE-2024-40477CRITICAL9.8A SQL injection vulnerability in "/oahms/admin/forgot-password.php" in PHPGurukul Old Age Home Management System v1.0 al...
CVE-2024-40472CRITICAL9.8Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php."
CVE-2024-3279CRITICAL9.1An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the i...
CVE-2024-39791CRITICAL9.8Stack-based buffer overflow vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeat...
CVE-2024-38989CRITICAL9.8izatop bunt v0.29.19 was discovered to contain a prototype pollution via the component /esm/qs.js. This vulnerability al...
CVE-2024-38219CRITICAL9Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2024-37023CRITICAL9.9Multiple OS command injection vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeater...
CVE-2024-22122CRITICAL9.1Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validat...
CVE-2024-21878CRITICAL9.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway ...
CVE-2024-21876CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enph...
CVE-2024-41161CRITICAL9.8Use of hard-coded credentials vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, so...
CVE-2024-42366CRITICAL9VRCX is an assistant/companion application for VRChat. In versions prior to 2024.03.23, a CefSharp browser with over-per...
CVE-2024-7490CRITICAL9.8Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause...
CVE-2024-42357CRITICAL9.8Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a s...
CVE-2024-42355CRITICAL9.8Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages wh...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now