2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-11590CRITICAL9.8A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affe...
CVE-2024-30896CRITICAL9.1InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows aut...
CVE-2024-11320CRITICAL9.8Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication me...
CVE-2024-51151CRITICAL9.8D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter ...
CVE-2024-52765CRITICAL9.8H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.
CVE-2024-52677CRITICAL9.8HkCms <= v2.3.2.240702 is vulnerable to file upload in the getFileName method in /app/common/library/Upload.php.
CVE-2024-48984CRITICAL9.8An issue was discovered in MBed OS 6.16.0. When parsing hci reports, the hci parsing software dynamically determines the...
CVE-2024-33439CRITICAL9.1An issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary O...
CVE-2024-29292CRITICAL9.1Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated re...
CVE-2024-52771CRITICAL9.1DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_v...
CVE-2024-52770CRITICAL9.8An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to...
CVE-2024-10094CRITICAL9.8Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code
CVE-2024-9479CRITICAL10Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Esc...
CVE-2024-9478CRITICAL10Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Esc...
CVE-2024-52443CRITICAL9.8Deserialization of Untrusted Data vulnerability in masikonis Geolocator geolocator allows Object Injection.This issue af...
CVE-2024-52442CRITICAL9.8Incorrect Privilege Assignment vulnerability in userplus UserPlus userplus allows Privilege Escalation.This issue affect...
CVE-2024-52441CRITICAL9.8Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Rajesh Thanoc...
CVE-2024-52440CRITICAL9.8Deserialization of Untrusted Data vulnerability in xpresslane Xpresslane Fast Checkout xpresslane-integration-for-woocom...
CVE-2024-52439CRITICAL9.8Deserialization of Untrusted Data vulnerability in Mark O'Donnell Team Rosters team-rosters allows Object Injection.This...
CVE-2024-10127CRITICAL9.8Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLD...
CVE-2024-52360CRITICAL9.8IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 is vulnerable to SQL injection. A remote attacker could send speci...
CVE-2024-52759CRITICAL9.8D-LINK DI-8003 v16.07.26A1 was discovered to contain a buffer overflow via the ip parameter in the ip_position_asp funct...
CVE-2024-52714CRITICAL9.8Tenda AC6 v2.0 v15.03.06.50 was discovered to contain a buffer overflow in the function 'fromSetSysTime.
CVE-2024-48694CRITICAL9.8File Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote att...
CVE-2024-48072CRITICAL9.8Weaver Ecology v9.* was discovered to contain a SQL injection vulnerability via the component /mobilemode/Action.jsp?inv...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now