2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-25189CRITICAL9.8libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authent...
CVE-2024-1207CRITICAL9.8The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmy...
CVE-2024-24216CRITICAL9.8Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection met...
CVE-2024-24091CRITICAL9.8Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file up...
CVE-2024-24202CRITICAL9.8An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and...
CVE-2024-24021CRITICAL9.8A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, ...
CVE-2024-24017CRITICAL9.8A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, l...
CVE-2024-24014CRITICAL9.8A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, l...
CVE-2024-24003CRITICAL9.8jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseRespon...
CVE-2024-22394CRITICAL9.8An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific con...
CVE-2024-24026CRITICAL9.8An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controll...
CVE-2024-24025CRITICAL9.8An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileCo...
CVE-2024-24024CRITICAL9.8An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.File...
CVE-2024-24023CRITICAL9.8A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, ...
CVE-2024-24018CRITICAL9.8A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset...
CVE-2024-24822CRITICAL9.1Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can cr...
CVE-2024-24563CRITICAL9.8Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. Arrays can be keyed by a signed integer, w...
CVE-2024-24811CRITICAL9.8SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unaut...
CVE-2024-24189CRITICAL9.8Jsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c.
CVE-2024-24188CRITICAL9.8Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c.
CVE-2024-24186CRITICAL9.8Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish...
CVE-2024-24133CRITICAL9.8Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.
CVE-2024-24303CRITICAL9.8SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before versio...
CVE-2024-1268CRITICAL9.8A vulnerability, which was classified as critical, was found in CodeAstro Restaurant POS System 1.0. This affects an unk...
CVE-2024-24019CRITICAL9.8A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now