2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-27348CRITICAL9.8RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1...
CVE-2024-29661CRITICAL9.8A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.
CVE-2024-32418CRITICAL9.8An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.
CVE-2024-31547CRITICAL9.1Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/item/view_ite...
CVE-2024-31546CRITICAL9.8Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/damage/view_d...
CVE-2024-32644CRITICAL9.1Evmos is a scalable, high-throughput Proof-of-Stake EVM blockchain that is fully compatible and interoperable with Ether...
CVE-2024-32038CRITICAL9.8Wazuh is a free and open source platform used for threat prevention, detection, and response. There is a buffer overflow...
CVE-2024-29966CRITICAL9.8Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appl...
CVE-2024-29204CRITICAL9.8A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthent...
CVE-2024-24996CRITICAL9.8A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated ...
CVE-2024-22061CRITICAL9.8A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenti...
CVE-2024-31750CRITICAL9.8SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the ...
CVE-2024-30938CRITICAL9.8SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID paramete...
CVE-2024-30923CRITICAL9.8SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where ...
CVE-2024-30922CRITICAL9.8SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in ...
CVE-2024-30564CRITICAL9.8An issue inandrei-tatar nora-firebase-common between v.1.0.41 and v.1.12.2 allows a remote attacker to execute arbitrary...
CVE-2024-2796CRITICAL9.3A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1....
CVE-2024-29021CRITICAL9Judge0 is an open-source online code execution system. The default configuration of Judge0 leaves the service vulnerable...
CVE-2024-28189CRITICAL10Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file ...
CVE-2024-28185CRITICAL10Judge0 is an open-source online code execution system. The application does not account for symlinks placed inside the s...
CVE-2024-3948CRITICAL9.8A vulnerability was found in SourceCodester Home Clean Service System 1.0. It has been rated as critical. Affected by th...
CVE-2024-32600CRITICAL9.6Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a throu...
CVE-2024-32599CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in Deepak anand WP Dummy Content Generator wp-du...
CVE-2024-32340CRITICAL9.6A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbit...
CVE-2024-3817CRITICAL9.8HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now