2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-35260CRITICAL9.8An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over...
CVE-2024-39669CRITICAL9.8In the Console in Soffid IAM before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent co...
CVE-2024-39376CRITICAL9.8TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performin...
CVE-2024-39375CRITICAL9.8TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileg...
CVE-2024-39374CRITICAL9.8TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed thro...
CVE-2024-6373CRITICAL9.8A vulnerability has been found in itsourcecode Online Food Ordering System up to 1.0 and classified as critical. This vu...
CVE-2024-6372CRITICAL9.8A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affec...
CVE-2024-6371CRITICAL9.8A vulnerability, which was classified as critical, has been found in itsourcecode Pool of Bethesda Online Reservation Sy...
CVE-2024-1107CRITICAL9.8Authorization Bypass Through User-Controlled Key vulnerability in Talya Informatics Travel APPS allows Exploiting Incorr...
CVE-2024-5535CRITICAL9.1Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer ma...
CVE-2024-0949CRITICAL9.8Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability...
CVE-2024-0947CRITICAL9.8Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics Elektraweb allows Sessi...
CVE-2024-37734CRITICAL9.8An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid par...
CVE-2024-1839CRITICAL10Intrado 911 Emergency Gateway login form is vulnerable to an unauthenticated blind time-based SQL injection, which may a...
CVE-2024-39243CRITICAL9.8An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/adm...
CVE-2024-4228CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive ...
CVE-2024-37252CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subs...
CVE-2024-37098CRITICAL9.8Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter.This issue affects Blo...
CVE-2024-5181CRITICAL9.8A command injection vulnerability exists in the mudler/localai version 2.14.0. The vulnerability arises from the applica...
CVE-2024-6060CRITICAL9.3An information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with access to the log files to ...
CVE-2024-35527CRITICAL9.8An arbitrary file upload vulnerability in /fileupload/upload.cfm in Daemon PTY Limited FarCry Core framework before 7.2....
CVE-2024-37843CRITICAL9.8Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
CVE-2024-21741CRITICAL9.8GigaDevice GD32E103C8T6 devices have Incorrect Access Control.
CVE-2024-5276CRITICAL9.1A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data.  Likely imp...
CVE-2024-4885CRITICAL9.8In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress Wh...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now