2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-34204CRITICAL9.8TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the set...
CVE-2024-34070CRITICAL9.6Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnera...
CVE-2024-33874CRITICAL9.8HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.
CVE-2024-32991CRITICAL9.8Permission verification vulnerability in the wpa_supplicant module Impact: Successful exploitation of this vulnerability...
CVE-2024-32964CRITICAL9Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system....
CVE-2024-32735CRITICAL9.8An issue regarding missing authentication for certain utilities exists in CyberPower PowerPanel Enterprise prior to v2.8...
CVE-2024-32700CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Kognetiks Kognetiks Chatbot for WordPress.This issue af...
CVE-2024-32622CRITICAL9.1HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_ex...
CVE-2024-32621CRITICAL9.8HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_...
CVE-2024-32615CRITICAL9.8HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c, caused ...
CVE-2024-32611CRITICAL9.8HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c.
CVE-2024-31810CRITICAL9.8TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at /etc/shadow.sample.
CVE-2024-31377CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This ...
CVE-2024-30802CRITICAL9.8An issue in Vehicle Management System 7.31.0.3_20230412 allows an attacker to escalate privileges via the login.html com...
CVE-2024-2257CRITICAL9.1This vulnerability exists in Digisol Router (DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02) due to impro...
CVE-2024-29895CRITICAL10Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x ...
CVE-2024-29212CRITICAL9.9Due to an unsafe de-serialization method used by the Veeam Service Provider Console(VSPC) server in communication betwe...
CVE-2024-29164CRITICAL9.8HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap, resulting in the corruption of the instruction...
CVE-2024-29159CRITICAL9.8HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instructio...
CVE-2024-29157CRITICAL9.8HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resulting in the corruption of the instruction pointer...
CVE-2024-28285CRITICAL9.8A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows ...
CVE-2024-27280CRITICAL9.8A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3...
CVE-2024-26517CRITICAL9.1SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a ...
CVE-2024-23473CRITICAL9.8The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. I...
CVE-2024-34257CRITICAL9.8TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized e...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now