2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-25943CRITICAL9.8iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contains a sessi...
CVE-2024-6265CRITICAL9.8The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for ...
CVE-2024-37371CRITICAL9.1In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling...
CVE-2024-5827CRITICAL9.8Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can injec...
CVE-2024-38371CRITICAL9.8authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when usin...
CVE-2024-6403CRITICAL9.8A vulnerability, which was classified as critical, has been found in Tenda A301 15.13.08.12. Affected by this issue is t...
CVE-2024-6402CRITICAL9.8A vulnerability classified as critical was found in Tenda A301 15.13.08.12. Affected by this vulnerability is the functi...
CVE-2024-3816CRITICAL9.8Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar...
CVE-2024-39704CRITICAL9.8Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev. 1.4.0 allows a remote attacker to ex...
CVE-2024-30110CRITICAL9.8HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A maliciou...
CVE-2024-39349CRITICAL9.8A vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjans...
CVE-2024-37282CRITICAL9.8It was identified that under certain specific preconditions, an API key that was originally created with a specific priv...
CVE-2024-6071CRITICAL10PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to...
CVE-2024-39705CRITICAL9.8NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data ...
CVE-2024-36059CRITICAL9.4Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers t...
CVE-2024-36072CRITICAL9.8Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnera...
CVE-2024-2973CRITICAL10An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router or co...
CVE-2024-6127CRITICAL9.8BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote...
CVE-2024-39208CRITICAL9.8luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.
CVE-2024-5980CRITICAL9.8A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path t...
CVE-2024-5826CRITICAL9.8In the latest version of vanna-ai/vanna, the `vanna.ask` function is vulnerable to remote code execution due to prompt i...
CVE-2024-5822CRITICAL9.8A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatG...
CVE-2024-5751CRITICAL9.8BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulner...
CVE-2024-3330CRITICAL9.9Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In th...
CVE-2024-2882CRITICAL9.3SDG Technologies PnPSCADA allows a remote attacker to attach various entities without requiring system authentication. T...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now