2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-38441CRITICAL9.8Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '...
CVE-2024-38439CRITICAL9.8Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN...
CVE-2024-38428CRITICAL9.1url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be inse...
CVE-2024-38395CRITICAL9.8In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution mi...
CVE-2024-6016CRITICAL9.8A vulnerability, which was classified as critical, has been found in itsourcecode Online Laundry Management System 1.0. ...
CVE-2024-6015CRITICAL9.8A vulnerability classified as critical was found in itsourcecode Online House Rental System 1.0. Affected by this vulner...
CVE-2024-6014CRITICAL9.8A vulnerability classified as critical has been found in itsourcecode Document Management System 1.0. Affected is an unk...
CVE-2024-6013CRITICAL9.8A vulnerability was found in itsourcecode Online Book Store 1.0. It has been rated as critical. This issue affects some ...
CVE-2024-6009CRITICAL9.8A vulnerability has been found in itsourcecode Event Calendar 1.0 and classified as critical. Affected by this vulnerabi...
CVE-2024-6007CRITICAL9.8A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects...
CVE-2024-4258CRITICAL9.8The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusi...
CVE-2024-3105CRITICAL9.9The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execu...
CVE-2024-5871CRITICAL9.8The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc...
CVE-2024-37831CRITICAL9.8Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter.
CVE-2024-37642CRITICAL9.1TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_p...
CVE-2024-34539CRITICAL9.4Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail ...
CVE-2024-33375CRITICAL9.8LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.
CVE-2024-33374CRITICAL9.8Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access th...
CVE-2024-5671CRITICAL9.8Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitra...
CVE-2024-37637CRITICAL9.8TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWizardCfg...
CVE-2024-3912CRITICAL9.8Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can e...
CVE-2024-2472CRITICAL9.1The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a...
CVE-2024-5577CRITICAL9.8The Where I Was, Where I Will Be plugin for WordPress is vulnerable to Remote File Inclusion in version <= 1.1.1 via the...
CVE-2024-4404CRITICAL9.6The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, ...
CVE-2024-4936CRITICAL9.8The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via th...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now