2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-2692CRITICAL9SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vuln...
CVE-2024-3273CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325...
CVE-2024-3272CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320...
CVE-2024-30568CRITICAL9.8Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.
CVE-2024-25096CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This i...
CVE-2024-24707CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Inject...
CVE-2024-31390CRITICAL9.9: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.T...
CVE-2024-31380CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. ...
CVE-2024-27972CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.Thi...
CVE-2024-3252CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Internship Portal Management System 1.0. This af...
CVE-2024-28515CRITICAL9.8Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary cod...
CVE-2024-30998CRITICAL9.8SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrar...
CVE-2024-31011CRITICAL9.8Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path ...
CVE-2024-31012CRITICAL9.8An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obt...
CVE-2024-30166CRITICAL9.1In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service...
CVE-2024-25864CRITICAL9.1Server Side Request Forgery (SSRF) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to exec...
CVE-2024-24724CRITICAL9.8Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Re...
CVE-2024-3209CRITICAL9.8A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of...
CVE-2024-3207CRITICAL9.8A vulnerability was found in ermig1979 Simd up to 6.0.134. It has been declared as critical. This vulnerability affects ...
CVE-2024-3204CRITICAL9.8A vulnerability has been found in c-blosc2 up to 2.13.2 and classified as critical. Affected by this vulnerability is th...
CVE-2024-3203CRITICAL9.8A vulnerability, which was classified as critical, was found in c-blosc2 up to 2.13.2. Affected is the function ndlz8_de...
CVE-2024-29432CRITICAL9.8Alldata v0.4.6 was discovered to contain a SQL injection vulnerability via the tablename parameter at /data/masterdata/d...
CVE-2024-27604CRITICAL9.8Alldata V0.4.6 is vulnerable to Command execution vulnerability. System commands can be deserialized.
CVE-2024-27602CRITICAL9.1Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.F...
CVE-2024-30621CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now