2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25096 | CRITICAL | 9.8 | 0.7% | Apr 3, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This i... |
| CVE-2024-24707 | CRITICAL | 9.9 | 0.7% | Apr 3, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Inject... |
| CVE-2024-31390 | CRITICAL | 9.9 | 0.9% | Apr 3, 2024 | : Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.T... |
| CVE-2024-31380 | CRITICAL | 9.9 | 0.8% | Apr 3, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. ... |
| CVE-2024-27972 | CRITICAL | 9.9 | 1.6% | Apr 3, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.Thi... |
| CVE-2024-3252 | CRITICAL | 9.8 | 0.8% | Apr 3, 2024 | A vulnerability classified as critical has been found in SourceCodester Internship Portal Management System 1.0. This af... |
| CVE-2024-28515 | CRITICAL | 9.8 | 1.5% | Apr 3, 2024 | Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary cod... |
| CVE-2024-30998 | CRITICAL | 9.8 | 1.2% | Apr 3, 2024 | SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrar... |
| CVE-2024-31011 | CRITICAL | 9.8 | 1.2% | Apr 3, 2024 | Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path ... |
| CVE-2024-31012 | CRITICAL | 9.8 | 1.2% | Apr 3, 2024 | An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obt... |
| CVE-2024-30166 | CRITICAL | 9.1 | 0.7% | Apr 3, 2024 | In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service... |
| CVE-2024-25864 | CRITICAL | 9.1 | 0.7% | Apr 3, 2024 | Server Side Request Forgery (SSRF) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to exec... |
| CVE-2024-24724 | CRITICAL | 9.8 | 26.1% | Apr 3, 2024 | Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Re... |
| CVE-2024-3209 | CRITICAL | 9.8 | 1.2% | Apr 2, 2024 | A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of... |
| CVE-2024-3207 | CRITICAL | 9.8 | 1.0% | Apr 2, 2024 | A vulnerability was found in ermig1979 Simd up to 6.0.134. It has been declared as critical. This vulnerability affects ... |
| CVE-2024-3204 | CRITICAL | 9.8 | 1.3% | Apr 2, 2024 | A vulnerability has been found in c-blosc2 up to 2.13.2 and classified as critical. Affected by this vulnerability is th... |
| CVE-2024-3203 | CRITICAL | 9.8 | 1.3% | Apr 2, 2024 | A vulnerability, which was classified as critical, was found in c-blosc2 up to 2.13.2. Affected is the function ndlz8_de... |
| CVE-2024-29432 | CRITICAL | 9.8 | 0.5% | Apr 2, 2024 | Alldata v0.4.6 was discovered to contain a SQL injection vulnerability via the tablename parameter at /data/masterdata/d... |
| CVE-2024-27604 | CRITICAL | 9.8 | 1.0% | Apr 2, 2024 | Alldata V0.4.6 is vulnerable to Command execution vulnerability. System commands can be deserialized. |
| CVE-2024-27602 | CRITICAL | 9.1 | 0.4% | Apr 2, 2024 | Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.F... |
| CVE-2024-30621 | CRITICAL | 9.8 | 0.7% | Apr 2, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan. |
| CVE-2024-30620 | CRITICAL | 9.8 | 0.8% | Apr 2, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan. |
| CVE-2024-2389 | CRITICAL | 9.8 | 93.9% | Apr 2, 2024 | In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified... |
| CVE-2024-31004 | CRITICAL | 9.8 | 1.5% | Apr 2, 2024 | An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_Stsd... |
| CVE-2024-31002 | CRITICAL | 9.8 | 1.4% | Apr 2, 2024 | Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now