2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-41319CRITICAL9.8TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter ...
CVE-2024-29070CRITICAL9.1On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend ser...
CVE-2024-6912CRITICAL9.8Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all pron...
CVE-2024-6806CRITICAL9.8The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These miss...
CVE-2024-6805CRITICAL9.8The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources. Thes...
CVE-2024-6794CRITICAL9.8A deserialization of untrusted data vulnerability exists in NI VeriStand Waveform Streaming Server that may result in r...
CVE-2024-6793CRITICAL9.8A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote c...
CVE-2024-40502CRITICAL9.8SQL injection vulnerability in Hospital Management System Project in ASP.Net MVC 1 allows aremote attacker to execute ar...
CVE-2024-39250CRITICAL9.8EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in t...
CVE-2024-38944CRITICAL9.8An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the...
CVE-2024-28698CRITICAL9.8Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code...
CVE-2024-39686CRITICAL9.8Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly i...
CVE-2024-39685CRITICAL9.8Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly i...
CVE-2024-41827CRITICAL9.8In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
CVE-2024-21552CRITICAL9.8All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attac...
CVE-2024-41318CRITICAL9.8TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet...
CVE-2024-41316CRITICAL9.8TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet...
CVE-2024-37998CRITICAL9.8A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base syste...
CVE-2024-38773CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adrian Tobey FormL...
CVE-2024-38759CRITICAL9.8Deserialization of Untrusted Data vulnerability in WP MEDIA SAS Search & Replace search-and-replace.This issue affects S...
CVE-2024-41704CRITICAL9.8LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.
CVE-2024-41703CRITICAL9.8LibreChat through 0.7.4-rc1 has incorrect access control for message updates.
CVE-2024-6970CRITICAL9.8A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0. Affected is an un...
CVE-2024-6966CRITICAL9.8A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0 and classified as critical. Affected b...
CVE-2024-6957CRITICAL9.8A vulnerability classified as critical has been found in itsourcecode University Management System 1.0. This affects an ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now