2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-32832CRITICAL9.8Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects L...
CVE-2024-46484CRITICAL9.8TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testser...
CVE-2024-13342CRITICAL9.8The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida...
CVE-2024-13985CRITICAL10A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to exe...
CVE-2024-13984CRITICAL10QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the...
CVE-2024-13981CRITICAL10LiveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co., Ltd., contains an arb...
CVE-2024-13980CRITICAL10H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulner...
CVE-2024-13979CRITICAL9.8A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers ...
CVE-2024-39335CRITICAL9.1Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed...
CVE-2024-53499CRITICAL9.8Jeewms v3.7 was discovered to contain a SQL injection vulnerability via the CgReportController API.
CVE-2024-53496CRITICAL9.8Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive compone...
CVE-2024-52786CRITICAL9.8An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute a...
CVE-2024-50645CRITICAL9.8MallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access ...
CVE-2024-50644CRITICAL9.8zhisheng17 blog 3.0.1-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to...
CVE-2024-45438CRITICAL9.1An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. Th...
CVE-2024-57155CRITICAL9.8Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access sensitive APIs without a t...
CVE-2024-57154CRITICAL9.8Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted pay...
CVE-2024-50640CRITICAL9.8jeewx-boot 1.3 has an authentication bypass vulnerability in the preHandle function
CVE-2024-57157CRITICAL9.8Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a t...
CVE-2024-12223CRITICAL9.3Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component...
CVE-2024-44373CRITICAL9.8A Path Traversal vulnerability in AllSky v2023.05.01 through v2024.12.06_06 allows an unauthenticated attacker to create...
CVE-2024-32640CRITICAL9.8MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, ...
CVE-2024-58266CRITICAL9.8The shlex crate before 1.2.1 for Rust allows unquoted and unescaped instances of the { and \xa0 characters, which may fa...
CVE-2024-6107CRITICAL9.8Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC c...
CVE-2024-9408CRITICAL9.8In Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endp...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now