2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-39931CRITICAL9.9Gogs through 0.13.0 allows deletion of internal files.
CVE-2024-39930CRITICAL9.9The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code ...
CVE-2024-39165CRITICAL9.8QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary cod...
CVE-2024-39844CRITICAL9.8In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.
CVE-2024-39223CRITICAL9.8An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the...
CVE-2024-32937CRITICAL9.8An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9....
CVE-2024-37082CRITICAL9.1When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be po...
CVE-2024-4708CRITICAL9.8mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device...
CVE-2024-38537CRITICAL9.8Fides is an open-source privacy engineering platform. `fides.js`, a client-side script used to interact with the consent...
CVE-2024-36404CRITICAL9.8GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6,...
CVE-2024-32755CRITICAL9.1Under certain circumstances the web interface will accept characters unrelated to the expected input.
CVE-2024-6440CRITICAL9.8A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0. It has been classified as crit...
CVE-2024-6439CRITICAL9.8A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0 and classified as critical. Thi...
CVE-2024-37185CRITICAL9.8in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through ...
CVE-2024-37077CRITICAL9.8in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through ...
CVE-2024-37030CRITICAL9.8in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through ...
CVE-2024-36260CRITICAL9.8in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through ...
CVE-2024-36243CRITICAL9.8in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through ...
CVE-2024-6172CRITICAL9.8The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f...
CVE-2024-39309CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability ...
CVE-2024-37762CRITICAL9.9MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code executio...
CVE-2024-5322CRITICAL9.1The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can l...
CVE-2024-39305CRITICAL9.1Envoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy...
CVE-2024-38368CRITICAL9.3trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older p...
CVE-2024-38367CRITICAL9.6trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. Prior to commit d4fa66f49cedab44...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now