2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-40541CRITICAL9.8my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para...
CVE-2024-40540CRITICAL9.8my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para...
CVE-2024-40539CRITICAL9.8my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para...
CVE-2024-39917CRITICAL9.8xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an i...
CVE-2024-38736CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Realtyna Realtyna Organic IDX plugin allows Code Inject...
CVE-2024-38734CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft...
CVE-2024-39914CRITICAL9.8FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker....
CVE-2024-37933CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in anhvnit Woocommerc...
CVE-2024-37927CRITICAL9.8Incorrect Privilege Assignment vulnerability in NooTheme Jobmonster noo-jobmonster allows Privilege Escalation.This issu...
CVE-2024-36522CRITICAL9.8The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when proc...
CVE-2024-6328CRITICAL9.8The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypa...
CVE-2024-6396CRITICAL9.8A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any fi...
CVE-2024-36435CRITICAL9.8An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM...
CVE-2024-6681CRITICAL9.8A vulnerability, which was classified as critical, has been found in witmy my-springsecurity-plus up to 2024-07-04. Affe...
CVE-2024-6680CRITICAL9.8A vulnerability classified as critical was found in witmy my-springsecurity-plus up to 2024-07-04. Affected by this vuln...
CVE-2024-6679CRITICAL9.8A vulnerability classified as critical has been found in witmy my-springsecurity-plus up to 2024-07-04. Affected is an u...
CVE-2024-6624CRITICAL9.8The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3...
CVE-2024-6385CRITICAL9.8An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 p...
CVE-2024-6397CRITICAL9.8The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all ...
CVE-2024-40618CRITICAL9.6Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when pr...
CVE-2024-6653CRITICAL9.8A vulnerability was found in code-projects Simple Task List 1.0. It has been declared as critical. This vulnerability af...
CVE-2024-6037CRITICAL9.1A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any loc...
CVE-2024-6036CRITICAL9.1A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending ...
CVE-2024-37310CRITICAL9EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp...
CVE-2024-25077CRITICAL9.8An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The Nonce used for on-the-f...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now