2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-48144CRITICAL9.1A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attacke...
CVE-2024-48143CRITICAL9.1A lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS v1.0 allows attackers t...
CVE-2024-48514CRITICAL9.8php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is abl...
CVE-2024-46478CRITICAL9.8HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681.
CVE-2024-48548CRITICAL9.3The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulne...
CVE-2024-48539CRITICAL9.8Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism.
CVE-2024-44206CRITICAL9.3An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17....
CVE-2024-10336CRITICAL9.8A vulnerability was found in SourceCodeHero Clothes Recommendation System 1.0. It has been rated as critical. This issue...
CVE-2024-10335CRITICAL9.8A vulnerability was found in SourceCodester Garbage Collection Management System 1.0. It has been declared as critical. ...
CVE-2024-48538CRITICAL9.8Incorrect access control in the firmware update and download processes of Neye3C v4.5.2.0 allows attackers to access sen...
CVE-2024-49681CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com W...
CVE-2024-48963CRITICAL9.8The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnera...
CVE-2024-20424CRITICAL9.9A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerl...
CVE-2024-20329CRITICAL9.9A vulnerability in the SSH subsystem of Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, r...
CVE-2024-49671CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Dogu Pekgoz AI Image Generator for Your Content & Featu...
CVE-2024-49669CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Alexander De Ridder INK Official ink-official allows Up...
CVE-2024-49668CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in christopherdewese1099 Verbalize WP verbalize-wp allows ...
CVE-2024-49658CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in ecomerciar Woocommerce Custom Profile Picture woo-custo...
CVE-2024-49653CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in james-eggers Portfolleo portfolleo allows Upload a Web ...
CVE-2024-49652CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-p...
CVE-2024-10293CRITICAL9.8A vulnerability was found in ZZCMS 2023. It has been classified as critical. Affected is the function Ebak_SetGotoPak of...
CVE-2024-10292CRITICAL9.8A vulnerability was found in ZZCMS 2023 and classified as critical. This issue affects some unknown processing of the fi...
CVE-2024-10291CRITICAL9.8A vulnerability has been found in ZZCMS 2023 and classified as critical. This vulnerability affects the function Ebak_Do...
CVE-2024-47903CRITICAL9.1A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fir...
CVE-2024-47902CRITICAL9.8A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fir...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now