2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-10934CRITICAL9.8In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS client and s...
CVE-2024-45971CRITICAL9.8Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c...
CVE-2024-45970CRITICAL9.8Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd75626...
CVE-2024-11250CRITICAL9.8A vulnerability was found in code-projects Inventory Management up to 1.0. It has been declared as critical. This vulner...
CVE-2024-52528CRITICAL9.3Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for...
CVE-2024-51164CRITICAL9.1Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allo...
CVE-2024-50724CRITICAL9.8KASO v9.0 was discovered to contain a SQL injection vulnerability via the person_id parameter at /cardcase/editcard.jsp.
CVE-2024-50649CRITICAL9.8The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.
CVE-2024-50648CRITICAL9.8yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improp...
CVE-2024-11244CRITICAL9.8A vulnerability classified as critical was found in code-projects Farmacia 1.0. This vulnerability affects unknown code ...
CVE-2024-11237CRITICAL9.8A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this...
CVE-2024-10534CRITICAL9.8Origin Validation Error vulnerability in Dataprom Informatics Personnel Attendance Control Systems (PACS) / Access Contr...
CVE-2024-10443CRITICAL9.8Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager...
CVE-2024-10924CRITICAL9.8The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass ...
CVE-2024-11120CRITICAL9.8Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit t...
CVE-2024-52308CRITICAL9.6The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH serve...
CVE-2024-48974CRITICAL9.3The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for ...
CVE-2024-48973CRITICAL9.3The debug port on the ventilator's serial interface is enabled by default. This could allow an attacker to send and rece...
CVE-2024-48971CRITICAL9.3The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This c...
CVE-2024-48970CRITICAL9.3The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and r...
CVE-2024-48967CRITICAL10The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activit...
CVE-2024-48966CRITICAL10The software tools used by service personnel to test & calibrate the ventilator do not support user authentication. An a...
CVE-2024-31695CRITICAL9.8A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS v2.85.4, allows attacker...
CVE-2024-9834CRITICAL9.3Improper data protection on the ventilator's serial interface could allow an attacker to send and receive messages that ...
CVE-2024-9832CRITICAL9.3There is no limit on the number of failed login attempts permitted with the Clinician Password or the Serial Number Clin...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now