2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-5635CRITICAL9.8A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been declared as critical. Affected ...
CVE-2024-36675CRITICAL9.1LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.
CVE-2024-36121CRITICAL9.1 netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP r...
CVE-2024-4219CRITICAL9.1Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, ...
CVE-2024-28103CRITICAL9.8Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permis...
CVE-2024-37273CRITICAL9.8An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execut...
CVE-2024-36858CRITICAL9.8An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute...
CVE-2024-36604CRITICAL9.8Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp functio...
CVE-2024-35672CRITICAL9.8Missing Authorization vulnerability in Netgsm.This issue affects Netgsm: from n/a through 2.9.19.
CVE-2024-35670CRITICAL9.8Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/...
CVE-2024-36400CRITICAL9.8nano-id is a unique string ID generator for Rust. Affected versions of the nano-id crate incorrectly generated IDs using...
CVE-2024-35700CRITICAL9.8Incorrect Privilege Assignment vulnerability in DeluxeThemes Userpro userpro.This issue affects Userpro: from n/a throug...
CVE-2024-35629CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-34551CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm ...
CVE-2024-33560CRITICAL9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore allows PHP...
CVE-2024-25600CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Inj...
CVE-2024-4253CRITICAL9.1A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.y...
CVE-2024-36104CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue...
CVE-2024-4180CRITICAL9.1The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering som...
CVE-2024-4552CRITICAL9.8The Social Login Lite For WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and...
CVE-2024-29974CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NA...
CVE-2024-29973CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar...
CVE-2024-29972CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326...
CVE-2024-36782CRITICAL9.8TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, whic...
CVE-2024-36783CRITICAL9.8TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the N...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now