2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-36470CRITICAL9.8In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific e...
CVE-2024-3412CRITICAL9.1The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file u...
CVE-2024-3050CRITICAL9.1The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowin...
CVE-2024-5150CRITICAL9.8The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including...
CVE-2024-35510CRITICAL9.8An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute ...
CVE-2024-35563CRITICAL9.8CDG-Server-V5.6.2.126.139 and earlier was discovered to contain a SQL injection vulnerability via the permissionId param...
CVE-2024-35344CRITICAL9.9Certain Anpviz products contain a hardcoded cryptographic key stored in the firmware of the device. This affects IPC-D25...
CVE-2024-35343CRITICAL9.8Certain Anpviz products allow unauthenticated users to download arbitrary files from the device's filesystem via a HTTP ...
CVE-2024-34854CRITICAL9.8F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`
CVE-2024-35324CRITICAL9.8Douchat 4.0.5 suffers from an arbitrary file upload vulnerability via Public/Plugins/webuploader/server/preview.php.
CVE-2024-33808CRITICAL9.8A SQL injection vulnerability in /model/get_timetable.php in campcodes Complete Web-Based School Management System 1.0 a...
CVE-2024-33806CRITICAL9.8A SQL injection vulnerability in /model/get_grade.php in campcodes Complete Web-Based School Management System 1.0 allow...
CVE-2024-33805CRITICAL9.8A SQL injection vulnerability in /model/get_student.php in campcodes Complete Web-Based School Management System 1.0 all...
CVE-2024-33801CRITICAL9.8A SQL injection vulnerability in /model/get_subject_routing.php in campcodes Complete Web-Based School Management System...
CVE-2024-33800CRITICAL9.8A SQL injection vulnerability in /model/get_student1.php in campcodes Complete Web-Based School Management System 1.0 al...
CVE-2024-33799CRITICAL9.8A SQL injection vulnerability in /model/get_teacher.php in campcodes Complete Web-Based School Management System 1.0 all...
CVE-2024-24963CRITICAL9.8A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of Au...
CVE-2024-24962CRITICAL9.8A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of Au...
CVE-2024-23601CRITICAL9.8A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A speciall...
CVE-2024-22590CRITICAL9.1The TLS engine in Kwik commit 745fd4e2 does not track the current state of the connection. This vulnerability can allow ...
CVE-2024-22187CRITICAL9.1A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality o...
CVE-2024-21785CRITICAL9.8A leftover debug code vulnerability exists in the Telnet Diagnostic Interface functionality of AutomationDirect P3-550E ...
CVE-2024-5274CRITICAL9.6Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside...
CVE-2024-3969CRITICAL9.8XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execu...
CVE-2024-35398CRITICAL9.8TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now