2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-25846CRITICAL9.1In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, ...
CVE-2024-25843CRITICAL9.8In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addon...
CVE-2024-1926CRITICAL9.8A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as c...
CVE-2024-25400CRITICAL9.8Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third partie...
CVE-2024-1923CRITICAL9.8A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as critical. Affected by...
CVE-2024-1403CRITICAL9.8In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the O...
CVE-2024-27905CRITICAL9.1** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Auror...
CVE-2024-1921CRITICAL9.8A vulnerability, which was classified as critical, was found in osuuu LightPicture up to 1.2.2. Affected is an unknown f...
CVE-2024-1918CRITICAL9.8A vulnerability has been found in Byzoro Smart S42 Management Platform up to 20240219 and classified as critical. Affect...
CVE-2024-1698CRITICAL9.8The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for...
CVE-2024-24095CRITICAL9.8Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection.
CVE-2024-25247CRITICAL9.8SQL Injection vulnerability in /app/api/controller/Store.php in Niushop B2B2C V5 allows attackers to run arbitrary SQL c...
CVE-2024-25751CRITICAL9.8A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote...
CVE-2024-25248CRITICAL9.8SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary S...
CVE-2024-24402CRITICAL9.8An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/n...
CVE-2024-24401CRITICAL9.8SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payl...
CVE-2024-27456CRITICAL9.1rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.
CVE-2024-27455CRITICAL9.1In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token wh...
CVE-2024-27447CRITICAL9.8pretix before 2024.1.1 mishandles file validation.
CVE-2024-27444CRITICAL9.8langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-...
CVE-2024-25925CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees ...
CVE-2024-25913CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a ...
CVE-2024-23605CRITICAL9.8A heap-based buffer overflow vulnerability exists in the GGUF library header.n_kv functionality of llama.cpp Commit 18c2...
CVE-2024-23496CRITICAL9.8A heap-based buffer overflow vulnerability exists in the GGUF library gguf_fread_str functionality of llama.cpp Commit 1...
CVE-2024-21836CRITICAL9.8A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now