2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-31546CRITICAL9.8Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/damage/view_d...
CVE-2024-32644CRITICAL9.1Evmos is a scalable, high-throughput Proof-of-Stake EVM blockchain that is fully compatible and interoperable with Ether...
CVE-2024-32038CRITICAL9.8Wazuh is a free and open source platform used for threat prevention, detection, and response. There is a buffer overflow...
CVE-2024-29966CRITICAL9.8Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appl...
CVE-2024-29204CRITICAL9.8A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthent...
CVE-2024-24996CRITICAL9.8A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated ...
CVE-2024-22061CRITICAL9.8A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenti...
CVE-2024-31750CRITICAL9.8SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the ...
CVE-2024-30938CRITICAL9.8SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID paramete...
CVE-2024-30923CRITICAL9.8SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where ...
CVE-2024-30922CRITICAL9.8SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in ...
CVE-2024-30564CRITICAL9.8An issue inandrei-tatar nora-firebase-common between v.1.0.41 and v.1.12.2 allows a remote attacker to execute arbitrary...
CVE-2024-2796CRITICAL9.3A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1....
CVE-2024-29021CRITICAL9Judge0 is an open-source online code execution system. The default configuration of Judge0 leaves the service vulnerable...
CVE-2024-28189CRITICAL10Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file ...
CVE-2024-28185CRITICAL10Judge0 is an open-source online code execution system. The application does not account for symlinks placed inside the s...
CVE-2024-3948CRITICAL9.8A vulnerability was found in SourceCodester Home Clean Service System 1.0. It has been rated as critical. Affected by th...
CVE-2024-32600CRITICAL9.6Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a throu...
CVE-2024-32599CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in Deepak anand WP Dummy Content Generator wp-du...
CVE-2024-32340CRITICAL9.6A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbit...
CVE-2024-3817CRITICAL9.8HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This...
CVE-2024-21990CRITICAL9.8ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that...
CVE-2024-31581CRITICAL9.8FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266...
CVE-2024-30990CRITICAL9.8SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows a...
CVE-2024-32161CRITICAL9.8jizhiCMS 2.5 suffers from a File upload vulnerability.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now