2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-25169CRITICAL9.8An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted reque...
CVE-2024-25927CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Joel Starnes postM...
CVE-2024-25910CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo...
CVE-2024-27099CRITICAL9.8The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect `AMQP_VALUE` f...
CVE-2024-25846CRITICAL9.1In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, ...
CVE-2024-25843CRITICAL9.8In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addon...
CVE-2024-1926CRITICAL9.8A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as c...
CVE-2024-25400CRITICAL9.8Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third partie...
CVE-2024-1923CRITICAL9.8A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as critical. Affected by...
CVE-2024-1403CRITICAL9.8In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the O...
CVE-2024-27905CRITICAL9.1** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Auror...
CVE-2024-1921CRITICAL9.8A vulnerability, which was classified as critical, was found in osuuu LightPicture up to 1.2.2. Affected is an unknown f...
CVE-2024-1918CRITICAL9.8A vulnerability has been found in Byzoro Smart S42 Management Platform up to 20240219 and classified as critical. Affect...
CVE-2024-1698CRITICAL9.8The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for...
CVE-2024-24095CRITICAL9.8Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection.
CVE-2024-25247CRITICAL9.8SQL Injection vulnerability in /app/api/controller/Store.php in Niushop B2B2C V5 allows attackers to run arbitrary SQL c...
CVE-2024-25751CRITICAL9.8A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote...
CVE-2024-25248CRITICAL9.8SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary S...
CVE-2024-24402CRITICAL9.8An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/n...
CVE-2024-24401CRITICAL9.8SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payl...
CVE-2024-27456CRITICAL9.1rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.
CVE-2024-27455CRITICAL9.1In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token wh...
CVE-2024-27447CRITICAL9.8pretix before 2024.1.1 mishandles file validation.
CVE-2024-27444CRITICAL9.8langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-...
CVE-2024-25925CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now