2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-40489CRITICAL9.8There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows a...
CVE-2024-44722CRITICAL9.8SysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd.
CVE-2024-57854CRITICAL9.1Net::NSCA::Client versions through 0.009002 for Perl uses a poor random number generator. Version v0.003 switched to us...
CVE-2024-55026CRITICAL9.8An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers...
CVE-2024-55024CRITICAL9.8An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v202310...
CVE-2024-55020CRITICAL9.8A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS ...
CVE-2024-58041CRITICAL9.1Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions. Smolder 1.51 and earl...
CVE-2024-5986CRITICAL9.1A vulnerability in h2oai/h2o-3 version 3.46.0.1 allows remote attackers to write arbitrary data to any file on the serve...
CVE-2024-2356CRITICAL9.6A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui ap...
CVE-2024-58338CRITICAL10Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed ...
CVE-2024-27480CRITICAL9.8givanz VvvebJs 1.7.2 is vulnerable to Insecure File Upload.
CVE-2024-25182CRITICAL9.8givanz VvvebJs 1.7.2 suffers from a File Upload vulnerability via save.php.
CVE-2024-25181CRITICAL9.1A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSR...
CVE-2024-44065CRITICAL9.8Time-based blind SQL Injection vulnerability in Cloudlog v2.6.15 at the endpoint /index.php/logbookadvanced/search in th...
CVE-2024-57521CRITICAL10SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the creat...
CVE-2024-27708CRITICAL9.6Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker t...
CVE-2024-49587CRITICAL9.1Glutton V1 service endpoints were exposed without any authentication on Gotham stacks, this could have allowed users tha...
CVE-2024-58311CRITICAL9.8Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access...
CVE-2024-58299CRITICAL9.8PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execu...
CVE-2024-14010CRITICAL9.8Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute a...
CVE-2024-58309CRITICAL9.8xbtitFM 4.1.18 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate databa...
CVE-2024-58308CRITICAL9.8Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authenticatio...
CVE-2024-58301CRITICAL9.3Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queri...
CVE-2024-58298CRITICAL9.2Compuware iStrobe Web 20.13 contains a pre-authentication remote code execution vulnerability that allows unauthenticate...
CVE-2024-58290CRITICAL9.3Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now