2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45369 | CRITICAL | 9.2 | 0.6% | Nov 22, 2024 | The web application uses a weak authentication mechanism to verify that a request is coming from an authenticated and au... |
| CVE-2024-8807 | CRITICAL | 9.8 | 1.6% | Nov 22, 2024 | Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers... |
| CVE-2024-8806 | CRITICAL | 9.8 | 1.6% | Nov 22, 2024 | Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers... |
| CVE-2024-5716 | CRITICAL | 9.8 | 1.6% | Nov 22, 2024 | Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypas... |
| CVE-2024-37782 | CRITICAL | 9.8 | 1.0% | Nov 22, 2024 | An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access s... |
| CVE-2024-53438 | CRITICAL | 9.8 | 0.5% | Nov 22, 2024 | EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by man... |
| CVE-2024-52723 | CRITICAL | 9.8 | 1.0% | Nov 22, 2024 | In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter... |
| CVE-2024-48862 | CRITICAL | 9.8 | 0.9% | Nov 22, 2024 | A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow rem... |
| CVE-2024-48860 | CRITICAL | 9.8 | 1.5% | Nov 22, 2024 | An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerabil... |
| CVE-2024-38643 | CRITICAL | 9.8 | 0.9% | Nov 22, 2024 | A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, ... |
| CVE-2024-8932 | CRITICAL | 9.8 | 1.3% | Nov 22, 2024 | In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_e... |
| CVE-2024-52053 | CRITICAL | 9.6 | 0.6% | Nov 21, 2024 | Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated att... |
| CVE-2024-51367 | CRITICAL | 9.8 | 0.8% | Nov 21, 2024 | An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.0.0.2 allows attacke... |
| CVE-2024-51366 | CRITICAL | 9.8 | 0.8% | Nov 21, 2024 | An arbitrary file upload vulnerability in the component \Roaming\Omega of OmegaT v6.0.1 allows attackers to execute arbi... |
| CVE-2024-53095 | CRITICAL | 9.8 | 0.2% | Nov 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free of network namespac... |
| CVE-2024-52289 | CRITICAL | 9.8 | 1.1% | Nov 21, 2024 | authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx co... |
| CVE-2024-52803 | CRITICAL | 9.8 | 2.3% | Nov 21, 2024 | LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has bee... |
| CVE-2024-8525 | CRITICAL | 10 | 1.4% | Nov 21, 2024 | An unrestricted upload of file with dangerous type in Automated Logic WebCTRL 7.0 could allow an unauthenticated user to... |
| CVE-2024-29224 | CRITICAL | 9.8 | 6.3% | Nov 21, 2024 | An OS command injection vulnerability exists in the NAT parameter of GoCast 1.1.3. A specially crafted HTTP request can ... |
| CVE-2024-28892 | CRITICAL | 9.8 | 6.4% | Nov 21, 2024 | An OS command injection vulnerability exists in the name parameter of GoCast 1.1.3. A specially crafted HTTP request can... |
| CVE-2024-21855 | CRITICAL | 9.8 | 2.0% | Nov 21, 2024 | A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP re... |
| CVE-2024-11592 | CRITICAL | 9.8 | 0.9% | Nov 21, 2024 | A vulnerability has been found in 1000 Projects Beauty Parlour Management System 1.0 and classified as critical. This vu... |
| CVE-2024-11591 | CRITICAL | 9.8 | 0.9% | Nov 21, 2024 | A vulnerability, which was classified as critical, was found in 1000 Projects Beauty Parlour Management System 1.0. This... |
| CVE-2024-11590 | CRITICAL | 9.8 | 0.8% | Nov 21, 2024 | A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affe... |
| CVE-2024-30896 | CRITICAL | 9.1 | 5.2% | Nov 21, 2024 | InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows aut... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now