2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-58286CRITICAL9.3dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through...
CVE-2024-45538CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-6...
CVE-2024-32641CRITICAL9.8Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 a...
CVE-2024-5539CRITICAL9.2The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows...
CVE-2024-47856CRITICAL9.8In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the...
CVE-2024-44659CRITICAL9.8PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.
CVE-2024-14003CRITICAL9.8Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data ...
CVE-2024-13999CRITICAL9.8Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP...
CVE-2024-13996CRITICAL9.8Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password...
CVE-2024-13994CRITICAL9.8Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option i...
CVE-2024-45162CRITICAL9.8A stack-based buffer overflow issue was discovered in the phddns client in Blu-Castle BCUM221E 1.0.0P220507 via the pass...
CVE-2024-33507CRITICAL9.1An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in For...
CVE-2024-58040CRITICAL9.1Crypt::RandomEncryption for Perl version 0.01 uses insecure rand() function during encryption.
CVE-2024-13150CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fayton Software an...
CVE-2024-13990CRITICAL9.3MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were deli...
CVE-2024-13151CRITICAL9.8CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ESBI In...
CVE-2024-13149CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive ...
CVE-2024-45434CRITICAL9.8OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetoo...
CVE-2024-43166CRITICAL9.8Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: bef...
CVE-2024-32444CRITICAL9.8Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue...
CVE-2024-28988CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that,...
CVE-2024-32832CRITICAL9.8Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects L...
CVE-2024-46484CRITICAL9.8TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testser...
CVE-2024-13342CRITICAL9.8The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida...
CVE-2024-13985CRITICAL10A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to exe...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now