2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-1874CRITICAL9.4In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array ...
CVE-2024-3342CRITICAL9.9The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attri...
CVE-2024-30804CRITICAL9.8An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbi...
CVE-2024-28322CRITICAL9.8SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allo...
CVE-2024-32881CRITICAL9.8Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access ...
CVE-2024-31601CRITICAL9.8An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v. 20240323 and before allows a...
CVE-2024-25343CRITICAL9.1Tenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords.
CVE-2024-33344CRITICAL9.8D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows r...
CVE-2024-32766CRITICAL10An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, ...
CVE-2024-32764CRITICAL9.9A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited,...
CVE-2024-0740CRITICAL9.8Eclipse Target Management: Terminal and Remote System Explorer (RSE) version <= 4.5.400 has a remote code execution vuln...
CVE-2024-3962CRITICAL9.8The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing ...
CVE-2024-22633CRITICAL9.8Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (...
CVE-2024-22632CRITICAL9.8Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (...
CVE-2024-33668CRITICAL9.1An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to id...
CVE-2024-33661CRITICAL9.1Portainer before 2.20.0 allows redirects when the target is not index.yaml.
CVE-2024-32651CRITICAL10changedetection.io is an open source web page change detection, website watcher, restock monitor and notification servic...
CVE-2024-0916CRITICAL10Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3....
CVE-2024-31615CRITICAL9.8ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.
CVE-2024-22391CRITICAL9.8A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroo...
CVE-2024-22373CRITICAL9.8An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malater...
CVE-2024-4165CRITICAL9.8A vulnerability, which was classified as critical, was found in Tenda G3 15.11.0.17(9502). Affected is the function modi...
CVE-2024-4164CRITICAL9.8A vulnerability, which was classified as critical, has been found in Tenda G3 15.11.0.17(9502). This issue affects the f...
CVE-2024-31266CRITICAL9.1Improper Control of Generation of Code ('Code Injection') vulnerability in AlgolPlus Advanced Order Export For WooCommer...
CVE-2024-30560CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in 大侠WP DX-Watermark.This issue affects DX-Watermark: from n/a through 1...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now