2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-58308CRITICAL9.8Quick.CMS 6.7 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authenticatio...
CVE-2024-58301CRITICAL9.3Purei CMS 1.0 contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queri...
CVE-2024-58298CRITICAL9.2Compuware iStrobe Web 20.13 contains a pre-authentication remote code execution vulnerability that allows unauthenticate...
CVE-2024-58290CRITICAL9.3Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers...
CVE-2024-58286CRITICAL9.3dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through...
CVE-2024-45538CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-6...
CVE-2024-32641CRITICAL9.8Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 a...
CVE-2024-5539CRITICAL9.2The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows...
CVE-2024-47856CRITICAL9.8In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the...
CVE-2024-44659CRITICAL9.8PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.
CVE-2024-14003CRITICAL9.8Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data ...
CVE-2024-13999CRITICAL9.8Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP...
CVE-2024-13996CRITICAL9.8Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password...
CVE-2024-13994CRITICAL9.8Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option i...
CVE-2024-45162CRITICAL9.8A stack-based buffer overflow issue was discovered in the phddns client in Blu-Castle BCUM221E 1.0.0P220507 via the pass...
CVE-2024-33507CRITICAL9.1An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in For...
CVE-2024-58040CRITICAL9.1Crypt::RandomEncryption for Perl version 0.01 uses insecure rand() function during encryption.
CVE-2024-13150CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fayton Software an...
CVE-2024-13990CRITICAL9.3MicroWorld eScan AV's update mechanism failed to ensure authenticity and integrity of updates: update packages were deli...
CVE-2024-13151CRITICAL9.8CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ESBI In...
CVE-2024-13149CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive ...
CVE-2024-45434CRITICAL9.8OpenSynergy BlueSDK (aka Blue SDK) through 6.x has a Use-After-Free. The specific flaw exists within the BlueSDK Bluetoo...
CVE-2024-43166CRITICAL9.8Incorrect Default Permissions vulnerability in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: bef...
CVE-2024-32444CRITICAL9.8Incorrect Privilege Assignment vulnerability in InspiryThemes RealHomes realhomes allows Privilege Escalation.This issue...
CVE-2024-28988CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that,...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now