2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-4884CRITICAL9.8In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress Wh...
CVE-2024-4883CRITICAL9.8In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This v...
CVE-2024-6308CRITICAL9.8A vulnerability was found in itsourcecode Simple Online Hotel Reservation System 1.0. It has been declared as critical. ...
CVE-2024-5989CRITICAL9.8Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injectio...
CVE-2024-5988CRITICAL9.8Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or r...
CVE-2024-5806CRITICAL9.8Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This i...
CVE-2024-5805CRITICAL9.1Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue ...
CVE-2024-39462CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: clk: bcm: dvp: Assign ->num before accessing ->hws ...
CVE-2024-5261CRITICAL9.8Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verificati...
CVE-2024-4641CRITICAL9.8OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format...
CVE-2024-6028CRITICAL9.8The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all v...
CVE-2024-6297CRITICAL10Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A m...
CVE-2024-4197CRITICAL9.8An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code exec...
CVE-2024-4196CRITICAL9.8An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code ex...
CVE-2024-36681CRITICAL9.8SQL Injection vulnerability in the module "Isotope" (pk_isotope) <=1.7.3 from Promokit.eu for PrestaShop allows attacker...
CVE-2024-34988CRITICAL9.8SQL injection vulnerability in the module "Complete for Create a Quote in Frontend + Backend Pro" (askforaquotemodul) <=...
CVE-2024-33898CRITICAL9.8Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An ...
CVE-2024-38902CRITICAL9.8H3C Magic R230 V100R002 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attack...
CVE-2024-37759CRITICAL9.8DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerabi...
CVE-2024-34313CRITICAL9.8An issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a pu...
CVE-2024-33879CRITICAL9.8An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileD...
CVE-2024-33278CRITICAL9.8Buffer Overflow vulnerability in ASUS router RT-AX88U with firmware versions v3.0.0.4.388_24198 allows a remote attacker...
CVE-2024-37231CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salon Booking System Sal...
CVE-2024-37228CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affe...
CVE-2024-37089CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consultin...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now