2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-45337CRITICAL9.1Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback...
CVE-2024-42448CRITICAL9.9From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is pos...
CVE-2024-12484CRITICAL9.8A vulnerability classified as critical was found in Codezips Technical Discussion Forum 1.0. This vulnerability affects ...
CVE-2024-11948CRITICAL9.8GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute a...
CVE-2024-53677CRITICAL9.8File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal an...
CVE-2024-11737CRITICAL9.8CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and a loss of confidential...
CVE-2024-54036CRITICAL9.3Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that c...
CVE-2024-54034CRITICAL9.3Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If...
CVE-2024-54032CRITICAL9.3Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that c...
CVE-2024-53480CRITICAL9.8Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` par...
CVE-2024-46340CRITICAL9.8TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user cr...
CVE-2024-46442CRITICAL9.8An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attac...
CVE-2024-11639CRITICAL9.8An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to...
CVE-2024-53866CRITICAL9.8The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one works...
CVE-2024-12286CRITICAL9.8MOBATIME Network Master Clock - DTS 4801 allows attackers to use SSH to gain initial access using default credentials.
CVE-2024-55547CRITICAL9.8SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e.
CVE-2024-45494CRITICAL9.8An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an ...
CVE-2024-45493CRITICAL9.8An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has int...
CVE-2024-54152CRITICAL9.3Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3...
CVE-2024-54751CRITICAL9.8COMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows at...
CVE-2024-5660CRITICAL9.8Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Co...
CVE-2024-55586CRITICAL9.8Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly p...
CVE-2024-47484CRITICAL9.8Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Impr...
CVE-2024-37143CRITICAL9.8Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8....
CVE-2024-53552CRITICAL9.8CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now