2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-13421CRITICAL9.8The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and includi...
CVE-2024-27781CRITICAL9An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS...
CVE-2024-12366CRITICAL9.8PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that c...
CVE-2024-52606CRITICAL9.8SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied al...
CVE-2024-13011CRITICAL9.8The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation ...
CVE-2024-55215CRITICAL9.8An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via the initialization inter...
CVE-2024-57707CRITICAL9.8An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and password components.
CVE-2024-36556CRITICAL9.1Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever KidsWatch Call Me 2 KW60 R3...
CVE-2024-36555CRITICAL9.8Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h an...
CVE-2024-36554CRITICAL9.8Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch Call Me KW-60 R36...
CVE-2024-57430CRITICAL9.8An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking System v2.0 allows attackers...
CVE-2024-57428CRITICAL9.3A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists due to unsanitized inp...
CVE-2024-57961CRITICAL9.8Out-of-bounds write vulnerability in the emcom module Impact: Successful exploitation of this vulnerability may cause fe...
CVE-2024-57959CRITICAL9.8Use-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vulnerability may cause...
CVE-2024-57958CRITICAL9.1Out-of-bounds array read vulnerability in the FFRT module Impact: Successful exploitation of this vulnerability may caus...
CVE-2024-51547CRITICAL9.8Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue aff...
CVE-2024-57520CRITICAL9.8Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_cre...
CVE-2024-57077CRITICAL9.1The latest version of utils-extend (1.0.8) is vulnerable to Prototype Pollution through the entry function(s) lib.extend...
CVE-2024-48445CRITICAL9.8An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and t...
CVE-2024-9644CRITICAL9.8The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the admini...
CVE-2024-9643CRITICAL9.8The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials i...
CVE-2024-57450CRITICAL9.8ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function.
CVE-2024-57099CRITICAL9.8ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in ...
CVE-2024-57098CRITICAL9.8Moss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into ...
CVE-2024-49839CRITICAL9.8Memory corruption during management frame processing due to mismatch in T2LM info element.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now