2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-5910CRITICAL9.8Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account ...
CVE-2024-37770CRITICAL9.114Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This...
CVE-2024-37113CRITICAL9.8Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This i...
CVE-2024-5217CRITICAL9.8ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earl...
CVE-2024-4879CRITICAL9.8ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platfo...
CVE-2024-6422CRITICAL9.8An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.
CVE-2024-21524CRITICAL9.1All versions of the package node-stringbuilder are vulnerable to Out-of-bounds Read due to incorrect memory length calcu...
CVE-2024-39071CRITICAL9.8Fujian Kelixun <=7.6.6.4391 is vulnerable to SQL Injection in send_event.php.
CVE-2024-37873CRITICAL9.8SQL injection vulnerability in view_payslip.php in Itsourcecode Payroll Management System Project In PHP With Source Cod...
CVE-2024-37870CRITICAL9.8SQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows...
CVE-2024-39171CRITICAL9.8Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code ...
CVE-2024-38089CRITICAL9.9Microsoft Defender for IoT Elevation of Privilege Vulnerability
CVE-2024-38077CRITICAL9.8Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVE-2024-38076CRITICAL9.8Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVE-2024-38074CRITICAL9.8Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVE-2024-36526CRITICAL9.8ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.
CVE-2024-27782CRITICAL9.8Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an at...
CVE-2024-6611CRITICAL9.8A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affec...
CVE-2024-6602CRITICAL9.8A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 1...
CVE-2024-6527CRITICAL9.3SQL Injection vulnerability in parameter "w" in file "druk.php" in MegaBIP software allows unauthorized attacker to disc...
CVE-2024-37934CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Saturday Drive Ninja Forms allows Code Inject...
CVE-2024-3596CRITICAL9RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (...
CVE-2024-39872CRITICAL9.9A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application ...
CVE-2024-37424CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Automattic Newspack Blocks allows Upload a Web Shell to...
CVE-2024-37420CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in WPZita Zita Elementor Site Library allows Upload a Web ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now