2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-24398CRITICAL9.8Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker ...
CVE-2024-23049CRITICAL9.8An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.
CVE-2024-0964CRITICAL9.4A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API reques...
CVE-2024-24543CRITICAL9.8Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allo...
CVE-2024-23054CRITICAL9.8An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution du...
CVE-2024-0323CRITICAL9.8The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TL...
CVE-2024-23109CRITICAL9.8An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ...
CVE-2024-23108CRITICAL9.8An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ...
CVE-2024-1225CRITICAL9.8A vulnerability classified as critical was found in QiboSoft QiboCMS X1 up to 1.0.6. Affected by this vulnerability is t...
CVE-2024-20011CRITICAL9.8In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote ...
CVE-2024-25089CRITICAL9.8Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC...
CVE-2024-1198CRITICAL9.8A vulnerability, which was classified as critical, was found in openBI up to 6.0.3. Affected is the function addxinzhi o...
CVE-2024-1197CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Testimonial Page Manager 1.0. This i...
CVE-2024-24757CRITICAL9.8open-irs is an issue response robot that reponds to issues in the installed repository. The `.env` file was accidentally...
CVE-2024-24029CRITICAL9.8JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.
CVE-2024-22108CRITICAL9.8An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureAp...
CVE-2024-0338CRITICAL9.8A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier. An attacker could execute a...
CVE-2024-23978CRITICAL9.8Heap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbit...
CVE-2024-24482CRITICAL9.8Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal.
CVE-2024-0685CRITICAL9.8The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second...
CVE-2024-22533CRITICAL9.8Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incomi...
CVE-2024-22319CRITICAL9.8 IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remo...
CVE-2024-23746CRITICAL9.8Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in ...
CVE-2024-22902CRITICAL9.8Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
CVE-2024-22901CRITICAL9.8Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now