2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-38983CRITICAL9.8Prototype Pollution in alykoshin mini-deep-assign v0.0.8 allows an attacker to execute arbitrary code or cause a Denial ...
CVE-2024-41611CRITICAL9.8In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers ...
CVE-2024-41610CRITICAL9.8D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attacker...
CVE-2024-39012CRITICAL9.8ais-ltd strategyen v0.4.0 was discovered to contain a prototype pollution via the function mergeObjects. This vulnerabil...
CVE-2024-39011CRITICAL9.8Prototype Pollution in chargeover redoc v2.0.9-rc.69 allows attackers to execute arbitrary code or cause a Denial of Ser...
CVE-2024-39010CRITICAL9.8chase-moskal snapstate v0.0.9 was discovered to contain a prototype pollution via the function attemptNestedProperty. Th...
CVE-2024-38986CRITICAL9.8Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (Do...
CVE-2024-38984CRITICAL9.8Prototype Pollution in lukebond json-override 0.2.0 allows attackers to to execute arbitrary code or cause a Denial of S...
CVE-2024-36572CRITICAL9.8Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the ...
CVE-2024-3930CRITICAL9.8In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.
CVE-2024-38909CRITICAL9.8Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension betwee...
CVE-2024-6699CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mikafon Electronic...
CVE-2024-41702CRITICAL9.8SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-38432CRITICAL9.8Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File
CVE-2024-7224CRITICAL9.8A vulnerability was found in SourceCodester Lot Reservation Management System 1.0 and classified as critical. Affected b...
CVE-2024-7223CRITICAL9.8A vulnerability has been found in SourceCodester Lot Reservation Management System 1.0 and classified as critical. Affec...
CVE-2024-7222CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Lot Reservation Management System 1.0. Af...
CVE-2024-7221CRITICAL9.8A vulnerability was determined in SourceCodester/Campcodes School Log Management System 1.0. This affects an unknown par...
CVE-2024-7220CRITICAL9.8A vulnerability was found in SourceCodester/Campcodes School Log Management System 1.0. Affected by this issue is some u...
CVE-2024-7219CRITICAL9.8A vulnerability has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected by this vulnerabil...
CVE-2024-5975CRITICAL9.1The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in...
CVE-2024-5765CRITICAL9.8The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a S...
CVE-2024-37858CRITICAL9.8SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via...
CVE-2024-28805CRITICAL9.1An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.
CVE-2024-41799CRITICAL9.9tgstation-server is a production scale tool for BYOND server management. Prior to 6.8.0, low permission users using the ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now