2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22144 | CRITICAL | 9 | 0.9% | Apr 25, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Eli Scheetz Anti-Malware Security and Brute-F... |
| CVE-2024-4173 | CRITICAL | 9.8 | 0.6% | Apr 25, 2024 | A vulnerability in Brocade SANnav exposes Kafka in the wan interface. The vulnerability could allow an unauthenticated... |
| CVE-2024-28825 | CRITICAL | 9.8 | 0.5% | Apr 24, 2024 | Improper restriction of excessive authentication attempts on some authentication methods in Checkmk before 2.3.0b5 (beta... |
| CVE-2024-32954 | CRITICAL | 9.1 | 0.6% | Apr 24, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Tribulant Newsletters.This issue affects Newsletters: f... |
| CVE-2024-32836 | CRITICAL | 9.1 | 0.8% | Apr 24, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay.This ... |
| CVE-2024-32709 | CRITICAL | 9.3 | 5.9% | Apr 24, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-... |
| CVE-2024-32948 | CRITICAL | 9.1 | 0.6% | Apr 24, 2024 | Missing Authorization vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.28. |
| CVE-2024-28613 | CRITICAL | 9.8 | 0.6% | Apr 24, 2024 | SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obta... |
| CVE-2024-32662 | CRITICAL | 9.8 | 0.8% | Apr 23, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulner... |
| CVE-2024-32659 | CRITICAL | 9.8 | 1.2% | Apr 23, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulner... |
| CVE-2024-32658 | CRITICAL | 9.8 | 1.4% | Apr 23, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulner... |
| CVE-2024-33215 | CRITICAL | 9.8 | 0.7% | Apr 23, 2024 | Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterfac... |
| CVE-2024-21511 | CRITICAL | 9.8 | 1.0% | Apr 23, 2024 | Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of t... |
| CVE-2024-32460 | CRITICAL | 9.8 | 1.9% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based based clients using `/bpp:32` legacy `GDI... |
| CVE-2024-32459 | CRITICAL | 9.8 | 3.8% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of... |
| CVE-2024-32458 | CRITICAL | 9.8 | 2.0% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP pri... |
| CVE-2024-32041 | CRITICAL | 9.8 | 1.9% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP pri... |
| CVE-2024-32040 | CRITICAL | 9.8 | 1.9% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP pri... |
| CVE-2024-32039 | CRITICAL | 9.8 | 2.3% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients using a version of FreeRDP prior ... |
| CVE-2024-27574 | CRITICAL | 9.1 | 0.6% | Apr 22, 2024 | SQL Injection vulnerability in Trainme Academy version Ichin v.1.3.2 allows a remote attacker to obtain sensitive inform... |
| CVE-2024-4040 | CRITICAL | 10 | 99.5% | Apr 22, 2024 | A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms all... |
| CVE-2024-32238 | CRITICAL | 9.8 | 53.2% | Apr 22, 2024 | H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accesse... |
| CVE-2024-31545 | CRITICAL | 9.4 | 0.6% | Apr 22, 2024 | Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/?page=user/ma... |
| CVE-2024-31666 | CRITICAL | 9.8 | 1.7% | Apr 22, 2024 | An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon... |
| CVE-2024-27349 | CRITICAL | 9.1 | 1.0% | Apr 22, 2024 | Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: f... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now