2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-53739CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-53507CRITICAL9.8A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems.
CVE-2024-53506CRITICAL9.8A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs.
CVE-2024-53505CRITICAL9.8A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent.
CVE-2024-53504CRITICAL9.8A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory.
CVE-2024-35368CRITICAL9.8FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c.
CVE-2024-35367CRITICAL9.1FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer
CVE-2024-35366CRITICAL9.1FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavfo...
CVE-2024-36622CRITICAL9.8In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vuln...
CVE-2024-49806CRITICAL9.8IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryp...
CVE-2024-49805CRITICAL9.8IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryp...
CVE-2024-52782CRITICAL9.8DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code...
CVE-2024-52781CRITICAL9.8DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code...
CVE-2024-52780CRITICAL9.8DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code...
CVE-2024-52779CRITICAL9.8DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code...
CVE-2024-52778CRITICAL9.8DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Code...
CVE-2024-52777CRITICAL9.8DCME-320 <=7.4.12.90, DCME-520 <=9.25.5.11, DCME-320-L, <=9.3.5.26, and DCME-720 <=9.1.5.11 are vulnerable to Remote Cod...
CVE-2024-48406CRITICAL9.8Buffer Overflow vulnerability in SunBK201 umicat through v.0.3.2 and fixed in v.0.3.3 allows an attacker to execute arbi...
CVE-2024-36671CRITICAL9.8nodemcu before v3.0.0-release_20240225 was discovered to contain an integer overflow via the getnum function at /modules...
CVE-2024-11992CRITICAL9.1Absolute path traversal vulnerability in Quick.CMS, version 6.7, the exploitation of which could allow remote users to b...
CVE-2024-50357CRITICAL9.8FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in t...
CVE-2024-11482CRITICAL9.8A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code exe...
CVE-2024-11979CRITICAL9.8DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This all...
CVE-2024-11970CRITICAL9.8A vulnerability classified as critical has been found in code-projects Concert Ticket Ordering System 1.0. Affected is a...
CVE-2024-11967CRITICAL9.8A vulnerability was found in PHPGurukul Complaint Management system 1.0. It has been classified as critical. Affected is...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now