2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-23674CRITICAL9.6The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication byp...
CVE-2024-23479CRITICAL9.6SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulner...
CVE-2024-23477CRITICAL9.6The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vu...
CVE-2024-23476CRITICAL9.6The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vu...
CVE-2024-25502CRITICAL9.8Directory Traversal vulnerability in flusity CMS v.2.4 allows a remote attacker to execute arbitrary code and obtain sen...
CVE-2024-23113CRITICAL9.8A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0....
CVE-2024-20720CRITICAL9.1Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special E...
CVE-2024-20719CRITICAL9.1Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vul...
CVE-2024-20738CRITICAL9.8Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability ...
CVE-2024-0390CRITICAL9.8INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by ...
CVE-2024-26264CRITICAL9.8EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page...
CVE-2024-26261CRITICAL9.8The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulner...
CVE-2024-26260CRITICAL9.8The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, all...
CVE-2024-24300CRITICAL9.84ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardle...
CVE-2024-25223CRITICAL9.8Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminV...
CVE-2024-25222CRITICAL9.8Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManage...
CVE-2024-25220CRITICAL9.8Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/E...
CVE-2024-25217CRITICAL9.8Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /om...
CVE-2024-25216CRITICAL9.8Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /apro...
CVE-2024-25215CRITICAL9.8Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aproces...
CVE-2024-25214CRITICAL9.8An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload int...
CVE-2024-25211CRITICAL9.8Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpo...
CVE-2024-25210CRITICAL9.8Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoi...
CVE-2024-25209CRITICAL9.8Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident param...
CVE-2024-23786CRITICAL9.3Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now