2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-3740CRITICAL9.8A vulnerability, which was classified as critical, has been found in cym1102 nginxWebUI up to 3.9.9. This issue affects ...
CVE-2024-3739CRITICAL9.8A vulnerability classified as critical was found in cym1102 nginxWebUI up to 3.9.9. This vulnerability affects unknown c...
CVE-2024-3738CRITICAL9.8A vulnerability classified as critical has been found in cym1102 nginxWebUI up to 3.9.9. This affects the function handl...
CVE-2024-3737CRITICAL9.8A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been rated as critical. Affected by this issue is th...
CVE-2024-3691CRITICAL9.8A vulnerability, which was classified as critical, has been found in PHPGurukul Small CRM 3.0. Affected by this issue is...
CVE-2024-28878CRITICAL9.6 IO-1020 Micro ELD downloads source code or an executable from an adjacent location and executes the code without suffi...
CVE-2024-30407CRITICAL9.2The Use of a Hard-coded Cryptographic Key vulnerability in Juniper Networks Juniper Cloud Native Router (JCNR) and conta...
CVE-2024-3704CRITICAL9.8SQL Injection Vulnerability has been found on OpenGnsys product affecting version 1.1.1d (Espeto). This vulnerability al...
CVE-2024-3685CRITICAL9.8A vulnerability, which was classified as critical, was found in DedeCMS 5.7.112-UTF8. Affected is an unknown function of...
CVE-2024-31818CRITICAL9.8Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page para...
CVE-2024-28718CRITICAL9.8An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py...
CVE-2024-3400CRITICAL10A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Netwo...
CVE-2024-22718CRITICAL9.6Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id pa...
CVE-2024-31678CRITICAL9.8Sourcecodester Loan Management System v1.0 is vulnerable to SQL Injection via the "password" parameter in the "login.php...
CVE-2024-21508CRITICAL9.8Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function d...
CVE-2024-29937CRITICAL9.8NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers ...
CVE-2024-27683CRITICAL9.8D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function hnap_main. An attacke...
CVE-2024-25935CRITICAL9.8Missing Authorization vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a throug...
CVE-2024-25912CRITICAL9.8Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.
CVE-2024-31996CRITICAL9.8XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc...
CVE-2024-31982CRITICAL9.8XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, an...
CVE-2024-31819CRITICAL9.8An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath ...
CVE-2024-29500CRITICAL9.8An issue in the kiosk mode of Secure Lockdown Multi Application Edition v2.00.219 allows attackers to execute arbitrary ...
CVE-2024-3157CRITICAL9.6Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had co...
CVE-2024-31461CRITICAL9.1Plane, an open-source project management tool, has a Server-Side Request Forgery (SSRF) vulnerability in versions prior ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now