2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-57811CRITICAL9.1In Eaton X303 3.5.16 - X303 3.5.17 Build 712, an attacker with network access to a XC-303 PLC can login as root over SSH...
CVE-2024-56323CRITICAL9.8OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19,...
CVE-2024-46310CRITICAL9.1Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary ...
CVE-2024-5743CRITICAL9.8An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve...
CVE-2024-42180CRITICAL9.8HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, incl...
CVE-2024-42175CRITICAL9.8HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and the...
CVE-2024-12877CRITICAL9.8The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all ...
CVE-2024-42172CRITICAL9.8HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tok...
CVE-2024-42168CRITICAL9.4HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that ...
CVE-2024-9132CRITICAL9.8The administrator is able to configure an insecure captive portal script
CVE-2024-12847CRITICAL9.8NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated a...
CVE-2024-57225CRITICAL9.8Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the re...
CVE-2024-57224CRITICAL9.8Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc...
CVE-2024-57223CRITICAL9.8Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc...
CVE-2024-56511CRITICAL9.8DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in t...
CVE-2024-29971CRITICAL9.8Scontain SCONE 5.8.0 has an interface vulnerability that leads to state corruption via injected signals.
CVE-2024-29970CRITICAL9.8Fortanix Enclave OS 3.36.1941-EM has an interface vulnerability that leads to state corruption via injected signals.
CVE-2024-57687CRITICAL9.8An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v...
CVE-2024-57686CRITICAL9.8A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record Sys...
CVE-2024-55225CRITICAL9.8An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, inc...
CVE-2024-55224CRITICAL9.6An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting...
CVE-2024-54724CRITICAL9.8PHPYun before 7.0.2 is vulnerable to code execution through backdoor-restricted arbitrary file writing and file inclusio...
CVE-2024-46505CRITICAL9.1Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.
CVE-2024-13285CRITICAL9.8Vulnerability in Drupal wkhtmltopdf.This issue affects wkhtmltopdf: *.*.
CVE-2024-13281CRITICAL9.1Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus:...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now