2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-48307CRITICAL9.8JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalD...
CVE-2024-10556CRITICAL9.8A vulnerability, which was classified as critical, was found in Codezips Pet Shop Management System 1.0. Affected is an ...
CVE-2024-51427CRITICAL9.8An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an...
CVE-2024-51424CRITICAL9.8An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an...
CVE-2024-48112CRITICAL9.8A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to ...
CVE-2024-48202CRITICAL9.8icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.
CVE-2024-9419CRITICAL9.8Client / Server PCs with the HP Smart Universal Printing Driver installed are potentially vulnerable to Remote Code Exec...
CVE-2024-10456CRITICAL9.8Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that...
CVE-2024-50419CRITICAL9.8Incorrect Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploitin...
CVE-2024-51298CRITICAL9.8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-31151CRITICAL9.8A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthoriz...
CVE-2024-10525CRITICAL9.8In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no rea...
CVE-2024-8512CRITICAL9.1The W3SPEEDSTER plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.26 v...
CVE-2024-50511CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in donimedia WP donimedia carousel wp-donimedia-carousel a...
CVE-2024-50510CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For Woocommerce ar-for-woocommerce allow...
CVE-2024-50507CRITICAL9.8Deserialization of Untrusted Data vulnerability in Daschmi DS.DownloadList dsdownloadlist allows Object Injection.This i...
CVE-2024-50503CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Deryck User Toolkit user-toolkit allows Authen...
CVE-2024-10509CRITICAL9.8A vulnerability, which was classified as critical, has been found in Codezips Online Institute Management System 1.0. Th...
CVE-2024-10507CRITICAL9.8A vulnerability classified as critical was found in Codezips Free Exam Hall Seating Management System 1.0. This vulnerab...
CVE-2024-51568CRITICAL9.8CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecut...
CVE-2024-51567CRITICAL9.8upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypas...
CVE-2024-51378CRITICAL9.8getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t...
CVE-2024-50428CRITICAL9.8Missing Authorization vulnerability in mondula2016 Multi Step Form multi-step-form allows Exploiting Incorrectly Configu...
CVE-2024-48573CRITICAL9.8A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and admin...
CVE-2024-48138CRITICAL9.8A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now