2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-35338CRITICAL9.8Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root.
CVE-2024-33182CRITICAL9.8Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId paramet...
CVE-2024-33180CRITICAL9.8Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId paramet...
CVE-2024-22442CRITICAL9.8The vulnerability could be remotely exploited to bypass authentication.
CVE-2024-39887CRITICAL9.8An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL ...
CVE-2024-40524CRITICAL9.8Directory Traversal vulnerability in xmind2testcase v.1.5 allows a remote attacker to execute arbitrary code via the web...
CVE-2024-4143CRITICAL9.8A potential security vulnerability has been identified in certain HP PC products using AMI BIOS, which might allow arbit...
CVE-2024-40624CRITICAL9.8TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In `torrentpier/library/includes...
CVE-2024-39915CRITICAL9.9Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the Livestatus API. This au...
CVE-2024-40416CRITICAL9.8A vulnerability in /goform/SetVirtualServerCfg in the sub_6320C function in Tenda AX1806 1.0.0.1 firmware leads to stack...
CVE-2024-40415CRITICAL9.8A vulnerability in /goform/SetStaticRouteCfg in the sub_519F4 function in Tenda AX1806 1.0.0.1 firmware leads to stack-b...
CVE-2024-40414CRITICAL9.8A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmware leads to stack-b...
CVE-2024-38492CRITICAL9.4This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by ...
CVE-2024-36456CRITICAL9.4This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by ...
CVE-2024-36455CRITICAL9.4An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM ...
CVE-2024-6745CRITICAL9.8A vulnerability classified as critical has been found in code-projects Simple Ticket Booking 1.0. Affected is an unknown...
CVE-2024-6744CRITICAL9.8The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Ove...
CVE-2024-6743CRITICAL9.8AguardNet's Space Management System does not properly validate user input, allowing unauthenticated remote attackers to ...
CVE-2024-39736CRITICAL9.8IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to HTTP header injection, caused by improper v...
CVE-2024-6728CRITICAL9.8A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been classified as critical. This affe...
CVE-2024-5450CRITICAL9.1The Bug Library WordPress plugin before 2.1.1 does not check the file type on user-submitted bug reports, allowing an un...
CVE-2024-40110CRITICAL9.8Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability...
CVE-2024-40542CRITICAL9.8my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para...
CVE-2024-40541CRITICAL9.8my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para...
CVE-2024-40540CRITICAL9.8my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now