2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-42190CRITICAL9.8HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker ...
CVE-2024-51360CRITICAL9.8An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor...
CVE-2024-51101CRITICAL9.8PHPGURUKUL Restaurant Table Booking System using PHP and MySQL v1.0 was discovered to contain a SQL injection vulnerabil...
CVE-2024-6914CRITICAL9.8An incorrect authorization vulnerability exists in multiple WSO2 products due to a business logic flaw in the account re...
CVE-2024-41198CRITICAL9.8An issue in Ocuco Innovation - REPORTS.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privileges...
CVE-2024-41197CRITICAL9.8An issue in Ocuco Innovation - INVCLIENT.EXE v2.10.24.5 allows attackers to bypass authentication and escalate privilege...
CVE-2024-41196CRITICAL9.8An issue in Ocuco Innovation - REPORTSERVER.EXE v2.10.24.13 allows attackers to bypass authentication and escalate privi...
CVE-2024-41195CRITICAL9.8An issue in Ocuco Innovation - INNOVASERVICEINTF.EXE v2.10.24.17 allows attackers to bypass authentication and escalate ...
CVE-2024-13955CRITICAL9.42nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if a...
CVE-2024-48853CRITICAL9.5An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a...
CVE-2024-8673CRITICAL9.1The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of S...
CVE-2024-6809CRITICAL9.8The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using ...
CVE-2024-6584CRITICAL9.1The 'wp_ajax_boost_proxy_ig' action allows administrators to make GET requests to arbitrary URLs.
CVE-2024-6159CRITICAL9.8The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a para...
CVE-2024-10865CRITICAL9.4Improper Input validation leads to XSS or Cross-site Scripting vulnerability in OpenText Advanced Authentication. This i...
CVE-2024-24780CRITICAL9.8Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create ...
CVE-2024-46506CRITICAL10NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because fun...
CVE-2024-56524CRITICAL9.1Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by add...
CVE-2024-56523CRITICAL9.1Radware Cloud Web Application Firewall (WAF) before 2025-05-07 allows remote attackers to bypass firewall filters by pla...
CVE-2024-12442CRITICAL9.8EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote s...
CVE-2024-11861CRITICAL9.8EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access.
CVE-2024-11617CRITICAL9.8The Envolve Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t...
CVE-2024-12378CRITICAL9.1On affected platforms running Arista EOS with secure Vxlan configured, restarting the Tunnelsec agent will result in pac...
CVE-2024-11186CRITICAL10On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to ...
CVE-2024-12225CRITICAL9.1A vulnerability was found in Quarkus in the quarkus-security-webauthn module. The Quarkus WebAuthn module publishes defa...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now