2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-37113CRITICAL9.8Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This i...
CVE-2024-5217CRITICAL9.8ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earl...
CVE-2024-4879CRITICAL9.8ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platfo...
CVE-2024-6422CRITICAL9.8An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.
CVE-2024-21524CRITICAL9.1All versions of the package node-stringbuilder are vulnerable to Out-of-bounds Read due to incorrect memory length calcu...
CVE-2024-39071CRITICAL9.8Fujian Kelixun <=7.6.6.4391 is vulnerable to SQL Injection in send_event.php.
CVE-2024-37873CRITICAL9.8SQL injection vulnerability in view_payslip.php in Itsourcecode Payroll Management System Project In PHP With Source Cod...
CVE-2024-37870CRITICAL9.8SQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows...
CVE-2024-39171CRITICAL9.8Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code ...
CVE-2024-38089CRITICAL9.9Microsoft Defender for IoT Elevation of Privilege Vulnerability
CVE-2024-38077CRITICAL9.8Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVE-2024-38076CRITICAL9.8Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVE-2024-38074CRITICAL9.8Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVE-2024-36526CRITICAL9.8ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.
CVE-2024-27782CRITICAL9.8Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an at...
CVE-2024-6611CRITICAL9.8A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affec...
CVE-2024-6602CRITICAL9.8A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 1...
CVE-2024-6527CRITICAL9.3SQL Injection vulnerability in parameter "w" in file "druk.php" in MegaBIP software allows unauthorized attacker to disc...
CVE-2024-37934CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Inject...
CVE-2024-3596CRITICAL9RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (...
CVE-2024-39872CRITICAL9.9A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application ...
CVE-2024-37424CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Automattic Newspack Blocks allows Upload a Web Shell to...
CVE-2024-37420CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in WPZita Zita Elementor Site Library allows Upload a Web ...
CVE-2024-37418CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects...
CVE-2024-37112CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Membership Softwar...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now