2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-25802CRITICAL9.8SKINsoft S-Museum 7.02.3 allows Unrestricted File Upload via the Add Media function. Unlike in CVE-2024-25801, the attac...
CVE-2024-25850CRITICAL9.8Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter
CVE-2024-22393CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through...
CVE-2024-25124CRITICAL9.8Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations ...
CVE-2024-25249CRITICAL9.8An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and en...
CVE-2024-25897CRITICAL9.8ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.
CVE-2024-25894CRITICAL9.8ChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter.
CVE-2024-25893CRITICAL9.1ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET param...
CVE-2024-1212CRITICAL9.8Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary s...
CVE-2024-25117CRITICAL9.8php-svg-lib is a scalable vector graphics (SVG) file parsing/rendering library. Prior to version 0.5.2, php-svg-lib fail...
CVE-2024-1702CRITICAL9.8A vulnerability was found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this iss...
CVE-2024-1709CRITICAL10ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel ...
CVE-2024-1701CRITICAL9.8A vulnerability has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by thi...
CVE-2024-1631CRITICAL9.1Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional p...
CVE-2024-25141CRITICAL9.1When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not ...
CVE-2024-22245CRITICAL9.6Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-...
CVE-2024-0794CRITICAL9.8Certain HP LaserJet Pro, HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to Remote C...
CVE-2024-25274CRITICAL9.8An arbitrary file upload vulnerability in the component /sysFile/upload of Novel-Plus v4.3.0-RC1 allows attackers to exe...
CVE-2024-23809CRITICAL9.8A double-free vulnerability exists in the BrainVision ASCII Header Parsing functionality of The Biosig Project libbiosig...
CVE-2024-23606CRITICAL9.8An out-of-bounds write vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 ...
CVE-2024-23313CRITICAL9.8An integer underflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 an...
CVE-2024-23310CRITICAL9.8A use-after-free vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Ma...
CVE-2024-23305CRITICAL9.8An out-of-bounds write vulnerability exists in the BrainVisionMarker Parsing functionality of The Biosig Project libbios...
CVE-2024-22097CRITICAL9.8A double-free vulnerability exists in the BrainVision Header Parsing functionality of The Biosig Project libbiosig Maste...
CVE-2024-21812CRITICAL9.8An integer overflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now