2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-21795CRITICAL9.8A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Project libbiosig 2.5....
CVE-2024-23114CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vul...
CVE-2024-22824CRITICAL9.8An issue in Timo v.2.0.3 allows a remote attacker to execute arbitrary code via the filetype restrictions in the UploadC...
CVE-2024-25198CRITICAL9.1Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robo...
CVE-2024-1554CRITICAL9.8The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional header...
CVE-2024-24794CRITICAL9.8A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5...
CVE-2024-24793CRITICAL9.8A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5...
CVE-2024-21896CRITICAL9.8The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the ...
CVE-2024-0715CRITICAL9.8Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue a...
CVE-2024-1651CRITICAL9.8Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application i...
CVE-2024-1638CRITICAL9.1The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characte...
CVE-2024-25626CRITICAL9.8Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless...
CVE-2024-25625CRITICAL9.3Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered...
CVE-2024-1597CRITICAL9.8pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the ...
CVE-2024-1344CRITICAL9.8Encrypted database credentials in LaborOfficeFree affecting version 19.10. This vulnerability allows an attacker to read...
CVE-2024-24722CRITICAL9.1An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an att...
CVE-2024-1512CRITICAL9.8The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union base...
CVE-2024-0610CRITICAL9.8The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to time-based blind SQL Injection via th...
CVE-2024-21495CRITICAL9.8Versions of the package github.com/greenpau/caddy-security before 1.0.42 are vulnerable to Insecure Randomness due to us...
CVE-2024-25320CRITICAL9.8Tongda OA v2017 and up to v11.9 was discovered to contain a SQL injection vulnerability via the $AFF_ID parameter at /af...
CVE-2024-22426CRITICAL9.8Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated...
CVE-2024-22425CRITICAL9.8Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains a brute force/dictionary attack vulnerability. An unauthe...
CVE-2024-24377CRITICAL9.8An issue in idocv v.14.1.3_20231228 allows a remote attacker to execute arbitrary code and obtain sensitive information ...
CVE-2024-25414CRITICAL9.8An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code vi...
CVE-2024-0031CRITICAL9.8In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now