2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-55062CRITICAL9.8Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers ...
CVE-2024-53356CRITICAL9.8Weak JWT Secret vulnerabilitiy in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote attackers to generate JW...
CVE-2024-53584CRITICAL9.8OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.
CVE-2024-47857CRITICAL9.8SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures w...
CVE-2024-53537CRITICAL9.1An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager...
CVE-2024-53320CRITICAL9.8Qualisys C++ SDK commit a32a21a was discovered to contain multiple stack buffer overflows via the GetCurrentFrame, SaveC...
CVE-2024-12267CRITICAL9.1The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited arbitrary file del...
CVE-2024-12248CRITICAL9.8Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send spe...
CVE-2024-13742CRITICAL9.8The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versi...
CVE-2024-13720CRITICAL9.1The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valida...
CVE-2024-12822CRITICAL9.8The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p...
CVE-2024-57665CRITICAL9.8JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability...
CVE-2024-57395CRITICAL9.8Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileg...
CVE-2024-54852CRITICAL9.8When LDAP connection is activated in Teedy versions between 1.9 to 1.12, the username field of the login form is vulnera...
CVE-2024-48852CRITICAL9.4Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly di...
CVE-2024-48849CRITICAL9.4Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauth...
CVE-2024-57965CRITICAL9.8In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a po...
CVE-2024-13448CRITICAL9.8The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ...
CVE-2024-12649CRITICAL9.8Buffer overflow in XPS data font processing of Small Office Multifunction Printers and Laser Printers(*) which may allow...
CVE-2024-12648CRITICAL9.8Buffer overflow in TIFF data EXIF tag processing of Small Office Multifunction Printers and Laser Printers(*) which may ...
CVE-2024-12647CRITICAL9.8Buffer overflow in CPCA font download processing of Small Office Multifunction Printers and Laser Printers(*) which may ...
CVE-2024-57548CRITICAL9.1CMSimple 5.16 allows the user to edit log.php file via print page.
CVE-2024-57052CRITICAL9.8An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter i...
CVE-2024-54542CRITICAL9.1An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, iOS 18.2 and i...
CVE-2024-54530CRITICAL9.1The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, visio...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now