2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-13905CRITICAL9.1The OneStore Sites plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin...
CVE-2024-57040CRITICAL9.8TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a ...
CVE-2024-53573CRITICAL9.8Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints ...
CVE-2024-50693CRITICAL9.1SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi...
CVE-2024-50689CRITICAL9.1SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi...
CVE-2024-50688CRITICAL9.8SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regar...
CVE-2024-50687CRITICAL9.1SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi...
CVE-2024-50686CRITICAL9.1SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi...
CVE-2024-50685CRITICAL9.1SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) v...
CVE-2024-47051CRITICAL9.9This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabili...
CVE-2024-30150CRITICAL9.1HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lea...
CVE-2024-56525CRITICAL9.8In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journ...
CVE-2024-53544CRITICAL9.8NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability...
CVE-2024-54820CRITICAL9.8XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login ...
CVE-2024-56897CRITICAL9.8Improper access control in the HTTP server in YI Car Dashcam v3.88 allows unrestricted file downloads, uploads, and API ...
CVE-2024-54756CRITICAL9.8A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to exe...
CVE-2024-57401CRITICAL9.8SQL Injection vulnerability in Uniclare Student portal v.2 and before allows a remote attacker to execute arbitrary code...
CVE-2024-13792CRITICAL9.8The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode executi...
CVE-2024-13789CRITICAL9.8The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.31 via de...
CVE-2024-37361CRITICAL9.9The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-5...
CVE-2024-56171CRITICAL9.8libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleID...
CVE-2024-56000CRITICAL9.8Incorrect Privilege Assignment vulnerability in SeventhQueen K Elements k-elements allows Privilege Escalation.This issu...
CVE-2024-55460CRITICAL9.8A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election Syste...
CVE-2024-39327CRITICAL9.9Incorrect Access Control vulnerability in Atos Eviden IDRA before 2.6.1 could allow the possibility to obtain CA signing...
CVE-2024-57045CRITICAL9.8A vulnerability in the D-Link DIR-859 router with firmware version A3 1.05 and earlier permits unauthorized individuals ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now