2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-29973CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the “setCookie” parameter in Zyxel NAS326 firmwar...
CVE-2024-29972CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** The command injection vulnerability in the CGI program "remote_help-cgi" in Zyxel NAS326...
CVE-2024-36782CRITICAL9.8TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, whic...
CVE-2024-36783CRITICAL9.8TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the N...
CVE-2024-34987CRITICAL9.1A SQL Injection vulnerability exists in the `ofrs/admin/index.php` script of PHPGurukul Online Fire Reporting System 1.2...
CVE-2024-31682CRITICAL9.8Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attac...
CVE-2024-4332CRITICAL9.3An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (T...
CVE-2024-37019CRITICAL9.8Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.
CVE-2024-5197CRITICAL9.1There exists interger overflows in libvpx in versions prior to 1.14.1. Calling vpx_img_alloc() with a large value of the...
CVE-2024-36568CRITICAL9.8Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=.
CVE-2024-0336CRITICAL9.4Missing Authentication for Critical Function vulnerability in EMTA Grup PDKS allows Exploiting Incorrectly Configured Ac...
CVE-2024-3829CRITICAL9.1qdrant/qdrant version 1.9.0-dev is vulnerable to arbitrary file read and write during the snapshot recovery process. Att...
CVE-2024-5404CRITICAL9.8An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mech...
CVE-2024-5311CRITICAL9.8DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbit...
CVE-2024-36042CRITICAL9.8Silverpeas before 6.3.5 allows authentication bypass by omitting the Password field to AuthenticationServlet, often prov...
CVE-2024-20067CRITICAL9.8In modem, there is a possible out of bounds write due to improper input invalidation. This could lead to remote denial o...
CVE-2024-5590CRITICAL9.8A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. This v...
CVE-2024-5589CRITICAL9.8A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This...
CVE-2024-36389CRITICAL9.8MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass
CVE-2024-36388CRITICAL9.8MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function
CVE-2024-27776CRITICAL9.8MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow ...
CVE-2024-3820CRITICAL10The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to SQL ...
CVE-2024-33999CRITICAL9.8The referrer URL used by MFA required additional sanitizing, rather than being used directly.
CVE-2024-5176CRITICAL9.4Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services wi...
CVE-2024-31030CRITICAL9.1An issue in coap_msg.c in Keith Cullen's FreeCoAP v.0.7 allows remote attackers to cause a Denial of Service or potentia...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now