2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-5515CRITICAL9.8A vulnerability was found in SourceCodester Stock Management System 1.0. It has been classified as critical. Affected is...
CVE-2024-1100CRITICAL10Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vadi Corporate Inf...
CVE-2024-5514CRITICAL9.8MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be r...
CVE-2024-4358CRITICAL9.8In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gai...
CVE-2024-36470CRITICAL9.8In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific e...
CVE-2024-3412CRITICAL9.1The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file u...
CVE-2024-3050CRITICAL9.1The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowin...
CVE-2024-5150CRITICAL9.8The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including...
CVE-2024-35510CRITICAL9.8An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute ...
CVE-2024-35563CRITICAL9.8CDG-Server-V5.6.2.126.139 and earlier was discovered to contain a SQL injection vulnerability via the permissionId param...
CVE-2024-35344CRITICAL9.9Certain Anpviz products contain a hardcoded cryptographic key stored in the firmware of the device. This affects IPC-D25...
CVE-2024-35343CRITICAL9.8Certain Anpviz products allow unauthenticated users to download arbitrary files from the device's filesystem via a HTTP ...
CVE-2024-34854CRITICAL9.8F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`
CVE-2024-35324CRITICAL9.8Douchat 4.0.5 suffers from an arbitrary file upload vulnerability via Public/Plugins/webuploader/server/preview.php.
CVE-2024-33808CRITICAL9.8A SQL injection vulnerability in /model/get_timetable.php in campcodes Complete Web-Based School Management System 1.0 a...
CVE-2024-33806CRITICAL9.8A SQL injection vulnerability in /model/get_grade.php in campcodes Complete Web-Based School Management System 1.0 allow...
CVE-2024-33805CRITICAL9.8A SQL injection vulnerability in /model/get_student.php in campcodes Complete Web-Based School Management System 1.0 all...
CVE-2024-33801CRITICAL9.8A SQL injection vulnerability in /model/get_subject_routing.php in campcodes Complete Web-Based School Management System...
CVE-2024-33800CRITICAL9.8A SQL injection vulnerability in /model/get_student1.php in campcodes Complete Web-Based School Management System 1.0 al...
CVE-2024-33799CRITICAL9.8A SQL injection vulnerability in /model/get_teacher.php in campcodes Complete Web-Based School Management System 1.0 all...
CVE-2024-24963CRITICAL9.8A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of Au...
CVE-2024-24962CRITICAL9.8A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of Au...
CVE-2024-23601CRITICAL9.8A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A speciall...
CVE-2024-22590CRITICAL9.1The TLS engine in Kwik commit 745fd4e2 does not track the current state of the connection. This vulnerability can allow ...
CVE-2024-22187CRITICAL9.1A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality o...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now