2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-6953CRITICAL9.8A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects...
CVE-2024-6951CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Simple Online Book Store System 1.0. This...
CVE-2024-6948CRITICAL9.8A vulnerability classified as critical has been found in Gargaj wuhu up to 3faad49bfcc3895e9ff76a591d05c8941273d120. Aff...
CVE-2024-6945CRITICAL9.8A vulnerability was found in Flute CMS 0.2.2.4-alpha. It has been classified as critical. This affects an unknown part o...
CVE-2024-38438CRITICAL9.8D-Link - CWE-294: Authentication Bypass by Capture-replay
CVE-2024-38437CRITICAL9.8D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel
CVE-2024-6933CRITICAL9.8A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettin...
CVE-2024-6636CRITICAL9.8The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...
CVE-2024-41603CRITICAL9.6Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout.
CVE-2024-39962CRITICAL9.8D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (...
CVE-2024-29736CRITICAL9.1A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attac...
CVE-2024-6205CRITICAL9.8The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using...
CVE-2024-6899CRITICAL9.8A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as critical. This vulnera...
CVE-2024-6898CRITICAL9.8A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as critical. This affec...
CVE-2024-35198CRITICAL9.8TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. TorchServe 's check ...
CVE-2024-39173CRITICAL9.8calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function ...
CVE-2024-0857CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software...
CVE-2024-5619CRITICAL9.6Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allo...
CVE-2024-5618CRITICAL9.9Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console...
CVE-2024-40629CRITICAL9.8JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand an...
CVE-2024-40628CRITICAL9.1JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand an...
CVE-2024-39911CRITICAL9.81Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent...
CVE-2024-39907CRITICAL9.81Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of t...
CVE-2024-6164CRITICAL9.8The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. T...
CVE-2024-41184CRITICAL9.8In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now