2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-1222CRITICAL9.8This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated...
CVE-2024-25250CRITICAL9.8SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code vi...
CVE-2024-28194CRITICAL9.8your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.8.0 use a hardcoded JSO...
CVE-2024-0799CRITICAL9.8An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui...
CVE-2024-2418CRITICAL9.8A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been declared as critical. Affected b...
CVE-2024-2172CRITICAL9.8The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to ...
CVE-2024-1071CRITICAL9.8The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2024-25153CRITICAL9.8A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outsid...
CVE-2024-2413CRITICAL9.8Intumit SmartRobot uses a fixed encryption key for authentication. Remote attackers can use this key to encrypt a string...
CVE-2024-24101CRITICAL9.8Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update.
CVE-2024-2406CRITICAL9.8A vulnerability, which was classified as critical, was found in Gacjie Server up to 1.0. This affects the function index...
CVE-2024-24093CRITICAL9.8SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Per...
CVE-2024-28114CRITICAL9.1Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to ...
CVE-2024-27317CRITICAL9.9In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip f...
CVE-2024-27135CRITICAL9.9Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java ...
CVE-2024-21400CRITICAL9Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
CVE-2024-21334CRITICAL9.8Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
CVE-2024-2394CRITICAL9.8A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by t...
CVE-2024-2393CRITICAL9.8A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been declared as critical. Affected by ...
CVE-2024-28553CRITICAL9.8Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the entrys parameter fromAddressNat function.
CVE-2024-28535CRITICAL9.8Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the mitInterface parameter of fromAddressNat function.
CVE-2024-22039CRITICAL9.8A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions < IP8), Cerberus PRO EN Fire Panel...
CVE-2024-26001CRITICAL9.8An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. Th...
CVE-2024-25996CRITICAL9.8An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is ...
CVE-2024-25995CRITICAL9.8An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or per...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now