2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-24321CRITICAL9.8An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 pa...
CVE-2024-24213CRITICAL9.8Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/que...
CVE-2024-25191CRITICAL9.8php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authent...
CVE-2024-25190CRITICAL9.8l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authent...
CVE-2024-25189CRITICAL9.8libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authent...
CVE-2024-1207CRITICAL9.8The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmy...
CVE-2024-24216CRITICAL9.8Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection met...
CVE-2024-24091CRITICAL9.8Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file up...
CVE-2024-24202CRITICAL9.8An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and...
CVE-2024-24021CRITICAL9.8A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, ...
CVE-2024-24017CRITICAL9.8A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, l...
CVE-2024-24014CRITICAL9.8A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, l...
CVE-2024-24003CRITICAL9.8jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseRespon...
CVE-2024-22394CRITICAL9.8An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific con...
CVE-2024-24026CRITICAL9.8An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controll...
CVE-2024-24025CRITICAL9.8An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileCo...
CVE-2024-24024CRITICAL9.8An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.File...
CVE-2024-24023CRITICAL9.8A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, ...
CVE-2024-24018CRITICAL9.8A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset...
CVE-2024-24822CRITICAL9.1Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can cr...
CVE-2024-24563CRITICAL9.8Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. Arrays can be keyed by a signed integer, w...
CVE-2024-24811CRITICAL9.8SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unaut...
CVE-2024-24189CRITICAL9.8Jsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c.
CVE-2024-24188CRITICAL9.8Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c.
CVE-2024-24186CRITICAL9.8Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now