2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-25096CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This i...
CVE-2024-24707CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Inject...
CVE-2024-31390CRITICAL9.9: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.T...
CVE-2024-31380CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. ...
CVE-2024-27972CRITICAL9.9Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.Thi...
CVE-2024-3252CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Internship Portal Management System 1.0. This af...
CVE-2024-28515CRITICAL9.8Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary cod...
CVE-2024-30998CRITICAL9.8SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrar...
CVE-2024-31011CRITICAL9.8Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path ...
CVE-2024-31012CRITICAL9.8An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obt...
CVE-2024-30166CRITICAL9.1In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service...
CVE-2024-25864CRITICAL9.1Server Side Request Forgery (SSRF) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to exec...
CVE-2024-24724CRITICAL9.8Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Re...
CVE-2024-3209CRITICAL9.8A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of...
CVE-2024-3207CRITICAL9.8A vulnerability was found in ermig1979 Simd up to 6.0.134. It has been declared as critical. This vulnerability affects ...
CVE-2024-3204CRITICAL9.8A vulnerability has been found in c-blosc2 up to 2.13.2 and classified as critical. Affected by this vulnerability is th...
CVE-2024-3203CRITICAL9.8A vulnerability, which was classified as critical, was found in c-blosc2 up to 2.13.2. Affected is the function ndlz8_de...
CVE-2024-29432CRITICAL9.8Alldata v0.4.6 was discovered to contain a SQL injection vulnerability via the tablename parameter at /data/masterdata/d...
CVE-2024-27604CRITICAL9.8Alldata V0.4.6 is vulnerable to Command execution vulnerability. System commands can be deserialized.
CVE-2024-27602CRITICAL9.1Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.F...
CVE-2024-30621CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan.
CVE-2024-30620CRITICAL9.8Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.
CVE-2024-2389CRITICAL9.8In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified...
CVE-2024-31004CRITICAL9.8An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_Stsd...
CVE-2024-31002CRITICAL9.8Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now