2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-3768CRITICAL9.8A vulnerability, which was classified as critical, has been found in PHPGurukul/itsourcecode News Portal 4.1. This issue...
CVE-2024-29844CRITICAL9.8Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to p...
CVE-2024-29836CRITICAL9.8The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr...
CVE-2024-3765CRITICAL9.8A vulnerability classified as critical was found in Xiongmai AHB7804R-MH-V2, AHB8004T-GL, AHB8008T-GL, AHB7004T-GS-V3, A...
CVE-2024-3740CRITICAL9.8A vulnerability, which was classified as critical, has been found in cym1102 nginxWebUI up to 3.9.9. This issue affects ...
CVE-2024-3739CRITICAL9.8A vulnerability classified as critical was found in cym1102 nginxWebUI up to 3.9.9. This vulnerability affects unknown c...
CVE-2024-3738CRITICAL9.8A vulnerability classified as critical has been found in cym1102 nginxWebUI up to 3.9.9. This affects the function handl...
CVE-2024-3737CRITICAL9.8A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been rated as critical. Affected by this issue is th...
CVE-2024-3691CRITICAL9.8A vulnerability, which was classified as critical, has been found in PHPGurukul Small CRM 3.0. Affected by this issue is...
CVE-2024-28878CRITICAL9.6 IO-1020 Micro ELD downloads source code or an executable from an adjacent location and executes the code without suffi...
CVE-2024-30407CRITICAL9.2The Use of a Hard-coded Cryptographic Key vulnerability in Juniper Networks Juniper Cloud Native Router (JCNR) and conta...
CVE-2024-3704CRITICAL9.8SQL Injection Vulnerability has been found on OpenGnsys product affecting version 1.1.1d (Espeto). This vulnerability al...
CVE-2024-3685CRITICAL9.8A vulnerability, which was classified as critical, was found in DedeCMS 5.7.112-UTF8. Affected is an unknown function of...
CVE-2024-31818CRITICAL9.8Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page para...
CVE-2024-28718CRITICAL9.8An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py...
CVE-2024-3400CRITICAL10A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Netwo...
CVE-2024-22718CRITICAL9.6Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id pa...
CVE-2024-31678CRITICAL9.8Sourcecodester Loan Management System v1.0 is vulnerable to SQL Injection via the "password" parameter in the "login.php...
CVE-2024-21508CRITICAL9.8Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function d...
CVE-2024-29937CRITICAL9.8NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers ...
CVE-2024-27683CRITICAL9.8D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function hnap_main. An attacke...
CVE-2024-25935CRITICAL9.8Missing Authorization vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a throug...
CVE-2024-25912CRITICAL9.8Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.
CVE-2024-31996CRITICAL9.8XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc...
CVE-2024-31982CRITICAL9.8XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, an...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now