2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-35339CRITICAL9.8Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/gofo...
CVE-2024-31510CRITICAL9.8An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker to escalate privileges via the crypto_sign_signatur...
CVE-2024-35592CRITICAL9.6An arbitrary file upload vulnerability in the Upload function of Box-IM v2.0 allows attackers to execute arbitrary code ...
CVE-2024-5315CRITICAL9.1Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could all...
CVE-2024-5314CRITICAL9.1Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could all...
CVE-2024-4544CRITICAL9.8The Pie Register - Social Sites Login (Add on) plugin for WordPress is vulnerable to authentication bypass in versions u...
CVE-2024-5296CRITICAL9.8D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote ...
CVE-2024-35570CRITICAL9.8An arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows ...
CVE-2024-35375CRITICAL9.8There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7....
CVE-2024-35080CRITICAL9.8An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code v...
CVE-2024-35079CRITICAL9.8An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary...
CVE-2024-35091CRITICAL9.8J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml...
CVE-2024-35086CRITICAL9.8J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in BpmTaskFromMapper.x...
CVE-2024-35084CRITICAL9.8J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysMsgPushMapper.xm...
CVE-2024-34935CRITICAL9.8A SQL injection vulnerability in /view/conversation_history_admin.php in Campcodes Complete Web-Based School Management ...
CVE-2024-34934CRITICAL9.8A SQL injection vulnerability in /view/emarks_range_grade_update_form.php in Campcodes Complete Web-Based School Managem...
CVE-2024-34932CRITICAL9.8A SQL injection vulnerability in /model/update_exam.php in Campcodes Complete Web-Based School Management System 1.0 all...
CVE-2024-34931CRITICAL9.8A SQL injection vulnerability in /model/update_subject.php in Campcodes Complete Web-Based School Management System 1.0 ...
CVE-2024-34929CRITICAL9.8A SQL injection vulnerability in /view/find_friends.php in Campcodes Complete Web-Based School Management System 1.0 all...
CVE-2024-34927CRITICAL9.8A SQL injection vulnerability in /model/update_classroom.php in Campcodes Complete Web-Based School Management System 1....
CVE-2024-5085CRITICAL9.8The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up t...
CVE-2024-5084CRITICAL9.8The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing fil...
CVE-2024-5168CRITICAL9.8Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerabi...
CVE-2024-4399CRITICAL9.1The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSR...
CVE-2024-29849CRITICAL9.8Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now