2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-37080CRITICAL9.8vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor wi...
CVE-2024-37079CRITICAL9.8vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor wi...
CVE-2024-6084CRITICAL9.8A vulnerability has been found in itsourcecode Pool of Bethesda Online Reservation System up to 1.0 and classified as cr...
CVE-2024-6083CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPVibe 11.0.46. Affected is an unknown function of the ...
CVE-2024-6067CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Music Class Enrollment System 1.0. Affected by this v...
CVE-2024-6066CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affecte...
CVE-2024-6065CRITICAL9.8A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been rated as critical. This issue a...
CVE-2024-34833CRITICAL9.8Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settin...
CVE-2024-37902CRITICAL10DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Framework in Java. DJL versions 0.1.0 through 0.27.0 do not pre...
CVE-2024-36543CRITICAL9.8Incorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to d...
CVE-2024-36575CRITICAL9.8A Prototype Pollution issue in getsetprop 1.1.0 allows an attacker to execute arbitrary code via global.accessor.
CVE-2024-36573CRITICAL9.8almela obx before v.0.0.4 has a Prototype Pollution issue which allows arbitrary code execution via the obx/build/index....
CVE-2024-36582CRITICAL9.8alexbinary object-deep-assign 1.0.11 is vulnerable to Prototype Pollution via the extend() method of Module.deepAssign (...
CVE-2024-36580CRITICAL9.8A Prototype Pollution issue in cdr0 sg 1.0.10 allows an attacker to execute arbitrary code.
CVE-2024-6057CRITICAL9.8Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allo...
CVE-2024-6048CRITICAL9.8Openfind's MailGates and MailAudit fail to properly filter user input when analyzing email attachments. An unauthenticat...
CVE-2024-6047CRITICAL9.8Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote ...
CVE-2024-5163CRITICAL9.8Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account secu...
CVE-2024-6043CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This af...
CVE-2024-6042CRITICAL9.8A vulnerability was found in itsourcecode Real Estate Management System 1.0. It has been rated as critical. Affected by ...
CVE-2024-34451CRITICAL9.1Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X...
CVE-2024-38396CRITICAL9.8An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in ...
CVE-2024-38468CRITICAL9.8Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.
CVE-2024-38466CRITICAL9.8Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.
CVE-2024-38462CRITICAL9.8iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mai...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now