2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-6684CRITICAL9.9Authentication Bypass Using an Alternate Path or Channel vulnerability in GST Electronics inohom Nova Panel N7 allows Au...
CVE-2024-42473CRITICAL9.8OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when cal...
CVE-2024-42470CRITICAL9.1openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. S...
CVE-2024-42469CRITICAL9.8openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. P...
CVE-2024-42467CRITICAL10openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. I...
CVE-2024-42001CRITICAL9.8An improper authentication vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeate...
CVE-2024-41577CRITICAL9.8An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arb...
CVE-2024-41570CRITICAL9.8An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send...
CVE-2024-41476CRITICAL9.8AMTT Hotel Broadband Operation System (HiBOS) V3.0.3.151204 and before is vulnerable to SQL Injection via /manager/card/...
CVE-2024-40486CRITICAL9.8A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execut...
CVE-2024-40482CRITICAL9.8An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System...
CVE-2024-40480CRITICAL9.8A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam S...
CVE-2024-40477CRITICAL9.8A SQL injection vulnerability in "/oahms/admin/forgot-password.php" in PHPGurukul Old Age Home Management System v1.0 al...
CVE-2024-40472CRITICAL9.8Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php."
CVE-2024-3279CRITICAL9.1An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the i...
CVE-2024-39791CRITICAL9.8Stack-based buffer overflow vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeat...
CVE-2024-38989CRITICAL9.8izatop bunt v0.29.19 was discovered to contain a prototype pollution via the component /esm/qs.js. This vulnerability al...
CVE-2024-38219CRITICAL9Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2024-37023CRITICAL9.9Multiple OS command injection vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeater...
CVE-2024-22122CRITICAL9.1Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validat...
CVE-2024-21878CRITICAL9.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway ...
CVE-2024-21876CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enph...
CVE-2024-41161CRITICAL9.8Use of hard-coded credentials vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, so...
CVE-2024-42366CRITICAL9VRCX is an assistant/companion application for VRChat. In versions prior to 2024.03.23, a CefSharp browser with over-per...
CVE-2024-7490CRITICAL9.8Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now