2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-48514CRITICAL9.8php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is abl...
CVE-2024-46478CRITICAL9.8HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681.
CVE-2024-48548CRITICAL9.3The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulne...
CVE-2024-48539CRITICAL9.8Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism.
CVE-2024-44206CRITICAL9.3An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17....
CVE-2024-10336CRITICAL9.8A vulnerability was found in SourceCodeHero Clothes Recommendation System 1.0. It has been rated as critical. This issue...
CVE-2024-10335CRITICAL9.8A vulnerability was found in SourceCodester Garbage Collection Management System 1.0. It has been declared as critical. ...
CVE-2024-48538CRITICAL9.8Incorrect access control in the firmware update and download processes of Neye3C v4.5.2.0 allows attackers to access sen...
CVE-2024-49681CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com W...
CVE-2024-48963CRITICAL9.8The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnera...
CVE-2024-20424CRITICAL9.9A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerl...
CVE-2024-20329CRITICAL9.9A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, r...
CVE-2024-49671CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Dogu Pekgoz AI Image Generator for Your Content & Featu...
CVE-2024-49669CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Alexander De Ridder INK Official ink-official allows Up...
CVE-2024-49668CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in christopherdewese1099 Verbalize WP verbalize-wp allows ...
CVE-2024-49658CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in ecomerciar Woocommerce Custom Profile Picture woo-custo...
CVE-2024-49653CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in james-eggers Portfolleo portfolleo allows Upload a Web ...
CVE-2024-49652CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-p...
CVE-2024-10293CRITICAL9.8A vulnerability was found in ZZCMS 2023. It has been classified as critical. Affected is the function Ebak_SetGotoPak of...
CVE-2024-10292CRITICAL9.8A vulnerability was found in ZZCMS 2023 and classified as critical. This issue affects some unknown processing of the fi...
CVE-2024-10291CRITICAL9.8A vulnerability has been found in ZZCMS 2023 and classified as critical. This vulnerability affects the function Ebak_Do...
CVE-2024-47903CRITICAL9.1A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fir...
CVE-2024-47902CRITICAL9.8A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fir...
CVE-2024-47901CRITICAL9.8A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fir...
CVE-2024-47575CRITICAL9.8A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now