2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-50393CRITICAL9.8A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the ...
CVE-2024-50389CRITICAL9.8A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote a...
CVE-2024-50388CRITICAL9.8An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerabil...
CVE-2024-50387CRITICAL9.8A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vuln...
CVE-2024-48863CRITICAL9.8A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allo...
CVE-2024-48859CRITICAL9.1An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploite...
CVE-2024-54750CRITICAL9.8Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attacker...
CVE-2024-54747CRITICAL9.8WAVLINK WN531P3 202383 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attacke...
CVE-2024-54745CRITICAL9.8WAVLINK WN701AE M01AE_V240305 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows ...
CVE-2024-54136CRITICAL9.8ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 5.5.1 Revision 199 and below is vulnera...
CVE-2024-54214CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in roninwp Revy revy allows Upload a Web Shell to a Web Se...
CVE-2024-53810CRITICAL9.1Missing Authorization vulnerability in N-Media Simple User Registration wp-registration allows Accessing Functionality N...
CVE-2024-53807CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in brandtoss WP Mails...
CVE-2024-53805CRITICAL9.8Missing Authorization vulnerability in brandtoss WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access...
CVE-2024-52335CRITICAL9.8A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF05). The affected application do not pr...
CVE-2024-51815CRITICAL9Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member allows Cod...
CVE-2024-51615CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Marka WordPress...
CVE-2024-10773CRITICAL9The product is vulnerable to pass-the-hash attacks in combination with hardcoded credentials of hidden user levels. This...
CVE-2024-53908CRITICAL9.8An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django...
CVE-2024-12155CRITICAL9.8The SV100 Companion plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e...
CVE-2024-38920CRITICAL9.1Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via...
CVE-2024-37863CRITICAL9.8Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow vi...
CVE-2024-37861CRITICAL9.8Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow vi...
CVE-2024-53442CRITICAL9.8whapa v1.59 is vulnerable to Command Injection via a crafted filename to the HTML reports component.
CVE-2024-41579CRITICAL9.8DTStack Taier 1.4.0 allows remote attackers to specify the jobName parameter in the console listNames function to cause ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now