2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-41610CRITICAL9.8D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attacker...
CVE-2024-39012CRITICAL9.8ais-ltd strategyen v0.4.0 was discovered to contain a prototype pollution via the function mergeObjects. This vulnerabil...
CVE-2024-39011CRITICAL9.8Prototype Pollution in chargeover redoc v2.0.9-rc.69 allows attackers to execute arbitrary code or cause a Denial of Ser...
CVE-2024-39010CRITICAL9.8chase-moskal snapstate v0.0.9 was discovered to contain a prototype pollution via the function attemptNestedProperty. Th...
CVE-2024-38986CRITICAL9.8Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (Do...
CVE-2024-38984CRITICAL9.8Prototype Pollution in lukebond json-override 0.2.0 allows attackers to to execute arbitrary code or cause a Denial of S...
CVE-2024-36572CRITICAL9.8Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the ...
CVE-2024-3930CRITICAL9.8In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.
CVE-2024-38909CRITICAL9.8Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension betwee...
CVE-2024-6699CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mikafon Electronic...
CVE-2024-41702CRITICAL9.8SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-38432CRITICAL9.8Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File
CVE-2024-7224CRITICAL9.8A vulnerability was found in SourceCodester Lot Reservation Management System 1.0 and classified as critical. Affected b...
CVE-2024-7223CRITICAL9.8A vulnerability has been found in SourceCodester Lot Reservation Management System 1.0 and classified as critical. Affec...
CVE-2024-7222CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Lot Reservation Management System 1.0. Af...
CVE-2024-7221CRITICAL9.8A vulnerability was determined in SourceCodester/Campcodes School Log Management System 1.0. This affects an unknown par...
CVE-2024-7220CRITICAL9.8A vulnerability was found in SourceCodester/Campcodes School Log Management System 1.0. Affected by this issue is some u...
CVE-2024-7219CRITICAL9.8A vulnerability has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected by this vulnerabil...
CVE-2024-5975CRITICAL9.1The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in...
CVE-2024-5765CRITICAL9.8The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a S...
CVE-2024-37858CRITICAL9.8SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via...
CVE-2024-28805CRITICAL9.1An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.
CVE-2024-41799CRITICAL9.9tgstation-server is a production scale tool for BYOND server management. Prior to 6.8.0, low permission users using the ...
CVE-2024-6576CRITICAL9.8Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This is...
CVE-2024-7196CRITICAL9.8A vulnerability was found in SourceCodester Complaints Report Management System 1.0. It has been declared as critical. A...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now