2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-56841CRITICAL9.1A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerab...
CVE-2024-12919CRITICAL9.8The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres...
CVE-2024-57811CRITICAL9.1In Eaton X303 3.5.16 - X303 3.5.17 Build 712, an attacker with network access to a XC-303 PLC can login as root over SSH...
CVE-2024-56323CRITICAL9.8OpenFGA is an authorization/permission engine. IN OpenFGA v1.3.8 to v1.8.2 (Helm chart openfga-0.1.38 to openfga-0.2.19,...
CVE-2024-46310CRITICAL9.1Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to modify and read arbitrary ...
CVE-2024-5743CRITICAL9.8An attacker could exploit the 'Use of Password Hash With Insufficient Computational Effort' vulnerability in EveHome Eve...
CVE-2024-42180CRITICAL9.8HCL MyXalytics is affected by a malicious file upload vulnerability. The application accepts invalid file uploads, incl...
CVE-2024-42175CRITICAL9.8HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and the...
CVE-2024-12877CRITICAL9.8The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all ...
CVE-2024-42172CRITICAL9.8HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tok...
CVE-2024-42168CRITICAL9.4HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that ...
CVE-2024-9132CRITICAL9.8The administrator is able to configure an insecure captive portal script
CVE-2024-12847CRITICAL9.8NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated a...
CVE-2024-57225CRITICAL9.8Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the re...
CVE-2024-57224CRITICAL9.8Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc...
CVE-2024-57223CRITICAL9.8Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc...
CVE-2024-56511CRITICAL9.8DataEase is an open source data visualization analysis tool. Prior to 2.10.4, there is a flaw in the authentication in t...
CVE-2024-29971CRITICAL9.8Scontain SCONE 5.8.0 has an interface vulnerability that leads to state corruption via injected signals.
CVE-2024-29970CRITICAL9.8Fortanix Enclave OS 3.36.1941-EM has an interface vulnerability that leads to state corruption via injected signals.
CVE-2024-57687CRITICAL9.8An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v...
CVE-2024-57686CRITICAL9.8A Cross Site Scripting (XSS) vulnerability was found in /landrecordsys/admin/contactus.php in PHPGurukul Land Record Sys...
CVE-2024-55225CRITICAL9.8An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, inc...
CVE-2024-55224CRITICAL9.6An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting...
CVE-2024-54724CRITICAL9.8PHPYun before 7.0.2 is vulnerable to code execution through backdoor-restricted arbitrary file writing and file inclusio...
CVE-2024-46505CRITICAL9.1Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now