2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-42004CRITICAL9.8A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially...
CVE-2024-41165CRITICAL9.1A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Wor...
CVE-2024-41145CRITICAL9.8A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.27...
CVE-2024-41138CRITICAL9.8A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work ...
CVE-2024-39804CRITICAL9.1A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can levera...
CVE-2024-56145CRITICAL9.8Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected ...
CVE-2024-52591CRITICAL9.3Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService...
CVE-2024-54383CRITICAL9.8Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Privilege...
CVE-2024-12373CRITICAL9.3A denial-of-service vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results in a b...
CVE-2024-12372CRITICAL9.3A denial-of-service and possible remote code execution vulnerability exists in the Rockwell Automation Power Monitor 100...
CVE-2024-12371CRITICAL9.3A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configur...
CVE-2024-56059CRITICAL9.8Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in farinspace Pa...
CVE-2024-56058CRITICAL9.8Deserialization of Untrusted Data vulnerability in denniskravetstns VRPConnector vrpconnector allows Object Injection.Th...
CVE-2024-4996CRITICAL9.8Use of a hard-coded password for a database administrator account created during Wapro ERP installation allows an attack...
CVE-2024-4995CRITICAL9.8Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypt...
CVE-2024-1610CRITICAL9.8In OPPO Store APP, there's a possible escalation of privilege due to improper input validation.
CVE-2024-12287CRITICAL9.8The Biagiotti Membership plugin for WordPress is vulnerable to authentication bypass in all versions up to, and includin...
CVE-2024-21546CRITICAL9.8Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through ...
CVE-2024-31668CRITICAL9.1rizin before v0.6.3 is vulnerable to Improper Neutralization of Special Elements via meta_set function in librz/analysis...
CVE-2024-29646CRITICAL9.8Buffer Overflow vulnerability in radarorg radare2 v.5.8.8 allows an attacker to execute arbitrary code via the name, typ...
CVE-2024-55516CRITICAL9.1A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 v3.90. The component affected by this issu...
CVE-2024-55515CRITICAL9.8A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue...
CVE-2024-55513CRITICAL9.1A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue...
CVE-2024-55496CRITICAL9.1A vulnerability has been found in the 1000projects Bookstore Management System PHP MySQL Project 1.0. This issue affects...
CVE-2024-54662CRITICAL9.1Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf configurations involving soc...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now