2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-33913CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability leading to Arbitrary File Upload in Xserver Migrator.This issue affects ...
CVE-2024-3955CRITICAL9.8URL GET parameter "logtime" utilized within the "downloadlog" function from "cbpi/http_endpoints/http_system.py" is subs...
CVE-2024-32971CRITICAL9Apollo Router is a configurable, graph router written in Rust to run a federated supergraph that uses Apollo Federation ...
CVE-2024-32962CRITICAL10xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuratio...
CVE-2024-4142CRITICAL9An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog A...
CVE-2024-33078CRITICAL9.8Tencent Libpag v4.3 is vulnerable to Buffer Overflow. A user can send a crafted image to trigger a overflow leading to r...
CVE-2024-23480CRITICAL9.8A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Clien...
CVE-2024-33512CRITICAL9.8There is a buffer overflow vulnerability in the underlying Local User Authentication Database service that could lead to...
CVE-2024-33511CRITICAL9.8There is a buffer overflow vulnerability in the underlying Automatic Reporting service that could lead to unauthenticate...
CVE-2024-26305CRITICAL9.8There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code...
CVE-2024-26304CRITICAL9.8There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated r...
CVE-2024-33775CRITICAL9.8An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a cr...
CVE-2024-33835CRITICAL9.8Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the remoteIp parameter from formSetSafeWanWebMan function.
CVE-2024-32018CRITICAL9RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit a...
CVE-2024-32017CRITICAL9RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit a...
CVE-2024-31225CRITICAL9RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit a...
CVE-2024-33768CRITICAL9.8lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source_over.
CVE-2024-3411CRITICAL9.1Implementations of IPMI Authenticated sessions does not provide enough randomness to protect from session hijacking, all...
CVE-2024-33308CRITICAL9.1An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to escalate pr...
CVE-2024-33275CRITICAL9.8SQL injection vulnerability in Webbax supernewsletter v.1.4.21 and before allows a remote attacker to escalate privilege...
CVE-2024-33273CRITICAL9.8SQL injection vulnerability in shipup before v.3.3.0 allows a remote attacker to escalate privileges via the getShopID f...
CVE-2024-33267CRITICAL9.8SQL Injection vulnerability in Hero hfheropayment v.1.2.5 and before allows an attacker to escalate privileges via the H...
CVE-2024-34048CRITICAL9.8O-RAN RIC I-Release e2mgr lacks array size checks in E2nodeConfigUpdateNotificationHandler.
CVE-2024-33350CRITICAL9.8Directory Traversal vulnerability in TaoCMS v.3.0.2 allows a remote attacker to execute arbitrary code and obtain sensit...
CVE-2024-33435CRITICAL9.8Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intellig...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now