2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-3000CRITICAL9.8A vulnerability classified as critical was found in code-projects Online Book System 1.0. This vulnerability affects unk...
CVE-2024-28815CRITICAL9.8A vulnerability in the BluStar component of Mitel InAttend 2.6 SP4 through 2.7 and CMG 8.5 SP4 through 8.6 could allow a...
CVE-2024-28335CRITICAL9.1Lektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is adde...
CVE-2024-2941CRITICAL9.8A vulnerability, which was classified as critical, has been found in Campcodes Online Examination System 1.0. Affected b...
CVE-2024-25735CRITICAL9.1An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext password...
CVE-2024-25393CRITICAL9.8A stack buffer overflow occurs in net/at/src/at_server.c in RT-Thread through 5.0.2.
CVE-2024-2934CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Todo List in Kanban Board 1.0. Affected by this vulne...
CVE-2024-2930CRITICAL9.8A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been declared as critical. Affected by this v...
CVE-2024-2927CRITICAL9.8A vulnerability was found in code-projects Mobile Shop 1.0. It has been classified as critical. Affected is an unknown f...
CVE-2024-2917CRITICAL9.8A vulnerability was found in Campcodes House Rental Management System 1.0. It has been declared as critical. Affected by...
CVE-2024-28545CRITICAL9.8Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter of formsetUsbUnload func...
CVE-2024-25421CRITICAL9.8An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CAC...
CVE-2024-2921CRITICAL9.8Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated u...
CVE-2024-2452CRITICAL9.8In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cau...
CVE-2024-29401CRITICAL9.8xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted a...
CVE-2024-29684CRITICAL9.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage...
CVE-2024-28048CRITICAL9.8OS command injection vulnerability exists in ffBull ver.4.11, which may allow a remote unauthenticated attacker to execu...
CVE-2024-29303CRITICAL9.8The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection
CVE-2024-28421CRITICAL9.8SQL Injection vulnerability in Razor 0.8.0 allows a remote attacker to escalate privileges via the ChannelModel::updatea...
CVE-2024-0901CRITICAL9.1Remotely executed SEGV and out of bounds read allows malicious packet sender to crash or cause an out of bounds read via...
CVE-2024-2873CRITICAL9.1A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create...
CVE-2024-29666CRITICAL9.8Insecure Permissions vulnerability in Vehicle Monitoring platform system CMSV6 v.7.31.0.2 through v.7.32.0.3 allows a re...
CVE-2024-29650CRITICAL9.8An issue in @thi.ng/paths v.5.1.62 and before allows a remote attacker to execute arbitrary code via the mutIn and mutIn...
CVE-2024-2865CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Qu...
CVE-2024-28393CRITICAL9.8SQL injection vulnerability in scalapay v.1.2.41 and before allows a remote attacker to escalate privileges via the Scal...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now