2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-9342CRITICAL9.8In Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation...
CVE-2024-39752CRITICAL9.8IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by not validating the type...
CVE-2024-38327CRITICAL9.8IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 is vulnerable to information exposure and further attacks due to an exp...
CVE-2024-25178CRITICAL9.1LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler i...
CVE-2024-25176CRITICAL9.8LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strf...
CVE-2024-13786CRITICAL9.8The education theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.6.10 via...
CVE-2024-12364CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mavi Yeşil Softwar...
CVE-2024-12150CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eron Software Woww...
CVE-2024-12143CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobilteg Mobile In...
CVE-2024-11739CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Case Informatics C...
CVE-2024-12827CRITICAL9.8The DWT - Directory & Listing WordPress Theme theme for WordPress is vulnerable to privilege escalation via account take...
CVE-2024-51978CRITICAL9.8An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password...
CVE-2024-37743CRITICAL9.8An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Comp...
CVE-2024-56731CRITICAL9.8Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the ....
CVE-2024-45347CRITICAL9.6An unauthorized access vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the val...
CVE-2024-53298CRITICAL9.8Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.1, contains a missing authorization vulnerability in the NFS expo...
CVE-2024-45208CRITICAL9.8The Versa Director SD-WAN orchestration platform which makes use of Cisco NCS application service. Active and Standby Di...
CVE-2024-56158CRITICAL9.8XWiki is a generic wiki platform. It's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGE...
CVE-2024-1244CRITICAL9.5Improper input validation in the OSSEC HIDS agent for Windows prior to version 3.8.0 allows an attacker in with control ...
CVE-2024-1243CRITICAL9.5Improper input validation in the Wazuh agent for Windows prior to version 4.8.0 allows an attacker with control over the...
CVE-2024-57190CRITICAL9.8Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP...
CVE-2024-55585CRITICAL9In the moPS App through 1.8.618, all users can access administrative API endpoints without additional authentication, re...
CVE-2024-22330CRITICAL9.8IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes i...
CVE-2024-13967CRITICAL9.4This vulnerability allows the successful attacker to gain unauthorized access to a configuration web page delivered by ...
CVE-2024-42191CRITICAL9.8HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now