2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-45369CRITICAL9.2The web application uses a weak authentication mechanism to verify that a request is coming from an authenticated and au...
CVE-2024-8807CRITICAL9.8Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
CVE-2024-8806CRITICAL9.8Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers...
CVE-2024-5716CRITICAL9.8Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypas...
CVE-2024-37782CRITICAL9.8An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access s...
CVE-2024-53438CRITICAL9.8EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by man...
CVE-2024-52723CRITICAL9.8In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter...
CVE-2024-48862CRITICAL9.8A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow rem...
CVE-2024-48860CRITICAL9.8An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerabil...
CVE-2024-38643CRITICAL9.8A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, ...
CVE-2024-8932CRITICAL9.8In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_e...
CVE-2024-52053CRITICAL9.6Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated att...
CVE-2024-51367CRITICAL9.8An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.0.0.2 allows attacke...
CVE-2024-51366CRITICAL9.8An arbitrary file upload vulnerability in the component \Roaming\Omega of OmegaT v6.0.1 allows attackers to execute arbi...
CVE-2024-53095CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free of network namespac...
CVE-2024-52289CRITICAL9.8authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx co...
CVE-2024-52803CRITICAL9.8LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has bee...
CVE-2024-8525CRITICAL10An unrestricted upload of file with dangerous type in Automated Logic WebCTRL 7.0 could allow an unauthenticated user to...
CVE-2024-29224CRITICAL9.8An OS command injection vulnerability exists in the NAT parameter of GoCast 1.1.3. A specially crafted HTTP request can ...
CVE-2024-28892CRITICAL9.8An OS command injection vulnerability exists in the name parameter of GoCast 1.1.3. A specially crafted HTTP request can...
CVE-2024-21855CRITICAL9.8A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP re...
CVE-2024-11592CRITICAL9.8A vulnerability has been found in 1000 Projects Beauty Parlour Management System 1.0 and classified as critical. This vu...
CVE-2024-11591CRITICAL9.8A vulnerability, which was classified as critical, was found in 1000 Projects Beauty Parlour Management System 1.0. This...
CVE-2024-11590CRITICAL9.8A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affe...
CVE-2024-30896CRITICAL9.1InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows aut...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now