2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-50942CRITICAL9.8qiwen-file v1.4.0 was discovered to contain a SQL injection vulnerability via the component /mapper/NoticeMapper.xml.
CVE-2024-11745CRITICAL9.8A vulnerability was found in Tenda AC8 16.03.34.09 and classified as critical. Affected by this issue is the function ro...
CVE-2024-11744CRITICAL9.8A vulnerability has been found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. Affected...
CVE-2024-49052CRITICAL9.8Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate p...
CVE-2024-49038CRITICAL9.6Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorize...
CVE-2024-49035CRITICAL9.8An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privil...
CVE-2024-11145CRITICAL9.8Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker t...
CVE-2024-11705CRITICAL9.1`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segme...
CVE-2024-11704CRITICAL9.8A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specif...
CVE-2024-11698CRITICAL9.8A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mo...
CVE-2024-11693CRITICAL9.8The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Wind...
CVE-2024-50375CRITICAL9.8A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by ...
CVE-2024-50374CRITICAL9.8A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff...
CVE-2024-50373CRITICAL9.8A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff...
CVE-2024-50372CRITICAL9.8A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff...
CVE-2024-50371CRITICAL9.8A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff...
CVE-2024-50370CRITICAL9.8A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff...
CVE-2024-11024CRITICAL9.8The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in...
CVE-2024-11680CRITICAL9.8ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated at...
CVE-2024-36248CRITICAL9.1API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model...
CVE-2024-35244CRITICAL9.1There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their ...
CVE-2024-33610CRITICAL9.1"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides log...
CVE-2024-28038CRITICAL9The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More ...
CVE-2024-50672CRITICAL9.8A NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to res...
CVE-2024-52787CRITICAL9.1An issue in the upload_documents method of libre-chat v0.0.6 allows attackers to execute a path traversal via supplying ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now