2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-54530CRITICAL9.1The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, visio...
CVE-2024-54512CRITICAL9.1The issue was addressed by removing the relevant flags. This issue is fixed in iOS 18.2 and iPadOS 18.2, watchOS 11.2. A...
CVE-2024-48841CRITICAL10Network access can be used to execute arbitrary code with elevated privileges. This issue affects FLXEON 9.3.4 and...
CVE-2024-55228CRITICAL9A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute ar...
CVE-2024-55227CRITICAL9A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to exec...
CVE-2024-57595CRITICAL9.8DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, whic...
CVE-2024-57590CRITICAL9.8TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",whi...
CVE-2024-50698CRITICAL9.8SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow due to bounds checks of...
CVE-2024-50695CRITICAL9.8SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to stack-based buffer overflow when parsing MQTT mess...
CVE-2024-50694CRITICAL9.8In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an MQTT message, the under...
CVE-2024-56404CRITICAL9.9In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privile...
CVE-2024-13545CRITICAL9.8The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1...
CVE-2024-57328CRITICAL9.8A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises bec...
CVE-2024-55194CRITICAL9.8OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component /OpenImageIO/fmath.h.
CVE-2024-55193CRITICAL9.8OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.
CVE-2024-55192CRITICAL9.8OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inline...
CVE-2024-55930CRITICAL9.8Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete fil...
CVE-2024-55926CRITICAL9.8A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through cr...
CVE-2024-52330CRITICAL9.5ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify...
CVE-2024-55971CRITICAL10SQL Injection vulnerability in the default configuration of the Logitime WebClock application <= 5.43.0 allows an unauth...
CVE-2024-52325CRITICAL9.6ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE con...
CVE-2024-13234CRITICAL9.8The Product Table by WBW plugin for WordPress is vulnerable to SQL Injection via the 'additionalCondition' parameter in ...
CVE-2024-52975CRITICAL9An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INF...
CVE-2024-12857CRITICAL9.8The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.8. Thi...
CVE-2024-13091CRITICAL9.8The WPBot Pro Wordpress Chatbot plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now