2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-6966CRITICAL9.8A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0 and classified as critical. Affected b...
CVE-2024-6957CRITICAL9.8A vulnerability classified as critical has been found in itsourcecode University Management System 1.0. This affects an ...
CVE-2024-6953CRITICAL9.8A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. This issue affects...
CVE-2024-6951CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Simple Online Book Store System 1.0. This...
CVE-2024-6948CRITICAL9.8A vulnerability classified as critical has been found in Gargaj wuhu up to 3faad49bfcc3895e9ff76a591d05c8941273d120. Aff...
CVE-2024-6945CRITICAL9.8A vulnerability was found in Flute CMS 0.2.2.4-alpha. It has been classified as critical. This affects an unknown part o...
CVE-2024-38438CRITICAL9.8D-Link - CWE-294: Authentication Bypass by Capture-replay
CVE-2024-38437CRITICAL9.8D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel
CVE-2024-6933CRITICAL9.8A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettin...
CVE-2024-6636CRITICAL9.8The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...
CVE-2024-41603CRITICAL9.6Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout.
CVE-2024-39962CRITICAL9.8D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (...
CVE-2024-29736CRITICAL9.1A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attac...
CVE-2024-6205CRITICAL9.8The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using...
CVE-2024-6899CRITICAL9.8A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as critical. This vulnera...
CVE-2024-6898CRITICAL9.8A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as critical. This affec...
CVE-2024-35198CRITICAL9.8TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. TorchServe 's check ...
CVE-2024-39173CRITICAL9.8calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function ...
CVE-2024-0857CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software...
CVE-2024-5619CRITICAL9.6Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allo...
CVE-2024-5618CRITICAL9.9Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console...
CVE-2024-40629CRITICAL9.8JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand an...
CVE-2024-40628CRITICAL9.1JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand an...
CVE-2024-39911CRITICAL9.81Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent...
CVE-2024-39907CRITICAL9.81Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now