2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-49748CRITICAL9.8In gatts_process_primary_service_req of gatt_sr.cc, there is a possible out of bounds write due to a heap buffer overflo...
CVE-2024-49747CRITICAL9.8In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the cod...
CVE-2024-24421CRITICAL9.8A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa...
CVE-2024-45479CRITICAL9.1SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upg...
CVE-2024-55959CRITICAL9.1Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.
CVE-2024-42936CRITICAL9.8The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Ex...
CVE-2024-54794CRITICAL9.1The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
CVE-2024-51919CRITICAL9Unrestricted Upload of File with Dangerous Type vulnerability in radykal Fancy Product Designer fancy-product-designer.T...
CVE-2024-51888CRITICAL9.8Incorrect Privilege Assignment vulnerability in favethemes Homey Login Register homey-login-register allows Privilege Es...
CVE-2024-51818CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in radykal Fancy Prod...
CVE-2024-49688CRITICAL9.8Deserialization of Untrusted Data vulnerability in reputeinfosystems ARPrice arprice allows Object Injection.This issue ...
CVE-2024-49655CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems ...
CVE-2024-32555CRITICAL9.8Incorrect Privilege Assignment vulnerability in InspiryThemes Easy Real Estate easy-real-estate allows Privilege Escalat...
CVE-2024-45647CRITICAL9.8IBM Security Verify Access 10.0.0 through 10.0.8 and IBM Security Verify Access Docker 10.0.0 through 10.0.8 could allow...
CVE-2024-41783CRITICAL9.1IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inje...
CVE-2024-38337CRITICAL9.1IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow an unauthorized attacker ...
CVE-2024-47113CRITICAL9.1IBM ICP - Voice Gateway 1.0.2, 1.0.2.4, 1.0.3, 1.0.4, 1.0.5, 1.0.6. 1.0.7, 1.0.7.1, and 1.0.8 could allow remote attacke...
CVE-2024-13375CRITICAL9.8The Adifier System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to...
CVE-2024-57035CRITICAL9.8WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.
CVE-2024-57034CRITICAL9.8WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.
CVE-2024-57032CRITICAL9.8WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the v...
CVE-2024-57031CRITICAL9.8WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.
CVE-2024-13503CRITICAL9.5Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Newtec NTC2218, NTC2250, NTC2299...
CVE-2024-13502CRITICAL9.3Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Newtec/iDire...
CVE-2024-57703CRITICAL9.8Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now