2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-27280CRITICAL9.8A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3...
CVE-2024-26517CRITICAL9.1SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a ...
CVE-2024-23473CRITICAL9.8The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. I...
CVE-2024-34257CRITICAL9.8TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized e...
CVE-2024-25533CRITICAL9.4Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFil...
CVE-2024-25532CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/ge...
CVE-2024-31961CRITICAL9.8A SQL injection vulnerability in unit.php in Sonic Shopfloor.guide before 3.1.3 allows remote attackers to execute arbit...
CVE-2024-25531CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtilit...
CVE-2024-25530CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtilit...
CVE-2024-25529CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_o...
CVE-2024-25527CRITICAL9.4RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffai...
CVE-2024-4654CRITICAL9.8A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This...
CVE-2024-32980CRITICAL9.1Spin is the developer tool for building and running serverless applications powered by WebAssembly. Prior to 2.4.3, some...
CVE-2024-32113CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue ...
CVE-2024-26579CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1....
CVE-2024-25525CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlo...
CVE-2024-25524CRITICAL9.4RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter ...
CVE-2024-25523CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemana...
CVE-2024-25522CRITICAL9.4RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the office_missive_id parameter at...
CVE-2024-25521CRITICAL9.4RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the txt_keyword parameter at get_c...
CVE-2024-25520CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys...
CVE-2024-25519CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/...
CVE-2024-25518CRITICAL9.4RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /Work...
CVE-2024-25517CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtilit...
CVE-2024-4393CRITICAL9.8The Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2. Th...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now