2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-54154CRITICAL9.8In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
CVE-2024-10576CRITICAL9.4Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast rece...
CVE-2024-52275CRITICAL9.8Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (fromWizardHandle modules) allows ...
CVE-2024-52274CRITICAL9.8Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (setDoubleL2tpConfig->guest_ip_che...
CVE-2024-52273CRITICAL9.8Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (setDoublePppoeConfig->guest_ip_ch...
CVE-2024-52272CRITICAL9.8Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (fromAdvSetLanip(overflow arg:lanM...
CVE-2024-54661CRITICAL9.8readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.
CVE-2024-51363CRITICAL9.8Insecure deserialization in Hodoku v2.3.0 to v2.3.2 allows attackers to execute arbitrary code.
CVE-2024-52544CRITICAL9.8An unauthenticated attacker can trigger a stack based buffer overflow in the DP Service (TCP port 3500). This vulnerabil...
CVE-2024-25020CRITICAL9.8IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted fi...
CVE-2024-53863CRITICAL9.1Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option ...
CVE-2024-40691CRITICAL9.8IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of ...
CVE-2024-25019CRITICAL9.8IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of fil...
CVE-2024-49415CRITICAL9.8Out-of-bound write in libsaped.so prior to SMR Dec-2024 Release 1 allows remote attackers to execute arbitrary code.
CVE-2024-53477CRITICAL9.8JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.ja...
CVE-2024-53900CRITICAL9.1Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
CVE-2024-52724CRITICAL9.8ZZCMS 2023 was discovered to contain a SQL injection vulnerability in /q/show.php.
CVE-2024-53990CRITICAL9.2The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT...
CVE-2024-52732CRITICAL9.1Incorrect access control in wms-Warehouse management system-zeqp v2.20.9.1 due to the token value of the zeqp system bei...
CVE-2024-46909CRITICAL9.8In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability t...
CVE-2024-10905CRITICAL9.8IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p2, IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p5, Identity...
CVE-2024-52476CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Stefan Bohacek Fediverse Embeds fediverse-embeds allows...
CVE-2024-12007CRITICAL9.8A vulnerability, which was classified as critical, was found in code-projects Farmacia 1.0. This affects an unknown part...
CVE-2024-53739CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-53507CRITICAL9.8A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now