2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-34405CRITICAL9.1Improper deep link validation in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to laun...
CVE-2024-30080CRITICAL9.8Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2024-2013CRITICAL10An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited all...
CVE-2024-2012CRITICAL9.8vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow uninten...
CVE-2024-2011CRITICAL9.8A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denia...
CVE-2024-5701CRITICAL9.8Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2024-5699CRITICAL9.8In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by ...
CVE-2024-5695CRITICAL9.8If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an asserti...
CVE-2024-3549CRITICAL9.9The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSort...
CVE-2024-36360CRITICAL9.8OS command injection vulnerability exists in awkblog v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and e...
CVE-2024-31401CRITICAL9Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an admin...
CVE-2024-29855CRITICAL9Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
CVE-2024-37014CRITICAL9.8Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_compo...
CVE-2024-36417CRITICAL9SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6...
CVE-2024-36412CRITICAL9.8SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6...
CVE-2024-32167CRITICAL9.1Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend...
CVE-2024-5597CRITICAL9.8Fuji Electric Monitouch V-SFT is vulnerable to a type confusion, which could cause a crash or code execution.
CVE-2024-35746CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Asghar Hatampoor BuddyPress Cover allows Code Injection...
CVE-2024-31611CRITICAL9.1SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.
CVE-2024-35677CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes MegaMenu ...
CVE-2024-35658CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeHigh Checkout Field...
CVE-2024-34762CRITICAL9.9Vulnerability discovered by executing a planned security audit. Improper Limitation of a Pathname to a Restricted Direc...
CVE-2024-35307CRITICAL9.8Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to e...
CVE-2024-35306CRITICAL9.8OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This...
CVE-2024-35305CRITICAL9.8Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora F...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now