2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-21741CRITICAL9.8GigaDevice GD32E103C8T6 devices have Incorrect Access Control.
CVE-2024-5276CRITICAL9.1A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data.  Likely imp...
CVE-2024-4885CRITICAL9.8In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress Wh...
CVE-2024-4884CRITICAL9.8In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress Wh...
CVE-2024-4883CRITICAL9.8In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This v...
CVE-2024-6308CRITICAL9.8A vulnerability was found in itsourcecode Simple Online Hotel Reservation System 1.0. It has been declared as critical. ...
CVE-2024-5989CRITICAL9.8Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injectio...
CVE-2024-5988CRITICAL9.8Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or r...
CVE-2024-5806CRITICAL9.8Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This i...
CVE-2024-5805CRITICAL9.1Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue ...
CVE-2024-39462CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: clk: bcm: dvp: Assign ->num before accessing ->hws ...
CVE-2024-5261CRITICAL9.8Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verificati...
CVE-2024-4641CRITICAL9.8OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format...
CVE-2024-6028CRITICAL9.8The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all v...
CVE-2024-6297CRITICAL10Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A m...
CVE-2024-4197CRITICAL9.8An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code exec...
CVE-2024-4196CRITICAL9.8An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code ex...
CVE-2024-36681CRITICAL9.8SQL Injection vulnerability in the module "Isotope" (pk_isotope) <=1.7.3 from Promokit.eu for PrestaShop allows attacker...
CVE-2024-34988CRITICAL9.8SQL injection vulnerability in the module "Complete for Create a Quote in Frontend + Backend Pro" (askforaquotemodul) <=...
CVE-2024-33898CRITICAL9.8Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An ...
CVE-2024-38902CRITICAL9.8H3C Magic R230 V100R002 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attack...
CVE-2024-37759CRITICAL9.8DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerabi...
CVE-2024-34313CRITICAL9.8An issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a pu...
CVE-2024-33879CRITICAL9.8An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileD...
CVE-2024-33278CRITICAL9.8Buffer Overflow vulnerability in ASUS router RT-AX88U with firmware versions v3.0.0.4.388_24198 allows a remote attacker...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now