2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-41198CRITICAL9.8An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges...
CVE-2024-41197CRITICAL9.8An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privilege...
CVE-2024-41196CRITICAL9.8An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privi...
CVE-2024-41195CRITICAL9.8An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate ...
CVE-2024-13955CRITICAL9.42nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if a...
CVE-2024-48853CRITICAL9.5An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a...
CVE-2024-8673CRITICAL9.1The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of S...
CVE-2024-6809CRITICAL9.8The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using ...
CVE-2024-6584CRITICAL9.1The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs.
CVE-2024-6159CRITICAL9.8The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a para...
CVE-2024-10865CRITICAL9.4Improper Input validation leads to XSS or Cross-site Scripting vulnerability in OpenText Advanced Authentication. This i...
CVE-2024-24780CRITICAL9.8Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create ...
CVE-2024-46506CRITICAL10NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because fun...
CVE-2024-56524CRITICAL9.1Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by add...
CVE-2024-56523CRITICAL9.1Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by pla...
CVE-2024-12442CRITICAL9.8EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote s...
CVE-2024-11861CRITICAL9.8EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access.
CVE-2024-11617CRITICAL9.8The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t...
CVE-2024-12378CRITICAL9.1On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in pac...
CVE-2024-11186CRITICAL10On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to ...
CVE-2024-12225CRITICAL9.1A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes defa...
CVE-2024-49846CRITICAL9.1Memory corruption while decoding of OTA messages from T3448 IE.
CVE-2024-57235CRITICAL9.8NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the iface pa...
CVE-2024-57234CRITICAL9.8NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname p...
CVE-2024-57233CRITICAL9.8NETGEAR RAX5 (AX1600 WiFi Router) v1.0.2.26 was discovered to contain a command injection vulnerability via the iface pa...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now