2024 CVE Vulnerabilities

39,233 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50489CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-wo...
CVE-2024-50487CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authe...
CVE-2024-50486CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allo...
CVE-2024-50477CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile...
CVE-2024-50450CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxon...
CVE-2024-50442HIGH7.2Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons royal-elementor-a...
CVE-2024-50416HIGH8.8Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce wpc-shop-as-customer ...
CVE-2024-50408HIGH8.8Deserialization of Untrusted Data vulnerability in Bob Namaste! LMS namaste-lms allows Object Injection.This issue affec...
CVE-2024-48074HIGH8An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a mali...
CVE-2024-10446HIGH7.2A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. Affected is an ...
CVE-2024-38821CRITICAL9.1Spring WebFlux applications that have Spring Security authorization rules on static resources can be bypassed under cert...
CVE-2024-9162HIGH7.2The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing...
CVE-2024-50307MEDIUM5.5Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If...
CVE-2024-48936MEDIUM5SchedMD Slurm before 24.05.4 has Incorrect Authorization. A mistake in authentication handling in stepmgr could permit a...
CVE-2024-10440CRITICAL9.8The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitra...
CVE-2024-10439HIGH7.5The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote ...
CVE-2024-10438HIGH7.5The eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypas...
CVE-2024-23843LOW2.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Genians Genian NAC...
CVE-2024-50067HIGH7.8In the Linux kernel, the following vulnerability has been resolved: uprobe: avoid out-of-bounds memory access of fetchi...
CVE-2024-10435MEDIUM6.3A vulnerability was found in didi Super-Jacoco 1.0. It has been declared as critical. This vulnerability affects unknown...
CVE-2024-10434CRITICAL9.8A vulnerability was found in Tenda AC1206 up to 20241027. It has been classified as critical. This affects the function ...
CVE-2024-50624MEDIUM5.9ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled m...
CVE-2024-50623CRITICAL9.8In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file up...
CVE-2024-10433MEDIUM6.1A vulnerability was found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as problematic. Affecte...
CVE-2024-10432CRITICAL9.8A vulnerability has been found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as critical. Affec...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now