2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-10279CRITICAL9.8A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. This vulnerability affects unknown code o...
CVE-2024-10278CRITICAL9.8A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. This affects an unknown part of the fil...
CVE-2024-10277CRITICAL9.8A vulnerability was found in ESAFENET CDG 5 and classified as critical. Affected by this issue is some unknown functiona...
CVE-2024-43924CRITICAL9.8Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrai...
CVE-2024-9947CRITICAL9.8The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4...
CVE-2024-46483CRITICAL9.8Xlight FTP Server <3.9.4.3 has an integer overflow vulnerability in the packet parsing logic of the SFTP server, which c...
CVE-2024-44812CRITICAL9.8SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the usern...
CVE-2024-43698CRITICAL9.8Kieback & Peter's DDC4000 series uses weak credentials, which may allow an unauthenticated attacker to get full admin ri...
CVE-2024-41717CRITICAL9.8Kieback & Peter's DDC4000 series is vulnerable to a path traversal vulnerability, which may allow an unauthenticated att...
CVE-2024-40494CRITICAL9.8Buffer Overflow in coap_msg.c in FreeCoAP allows remote attackers to execute arbitrary code or cause a denial of service...
CVE-2024-40493CRITICAL9.8Null Pointer Dereference in `coap_client_exchange_blockwise2` function in Keith Cullen FreeCoAP 1.0 allows remote attack...
CVE-2024-26519CRITICAL9An issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a cr...
CVE-2024-48919CRITICAL9.2Cursor is a code editor built for programming with AI. Prior to Sep 27, 2024, if a user generated a terminal command via...
CVE-2024-48904CRITICAL9.8An command injection vulnerability in Trend Micro Cloud Edge could allow a remote attacker to execute arbitrary code on ...
CVE-2024-46902CRITICAL9.1A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose...
CVE-2024-9129CRITICAL9.3In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered. Reported by Dylan Ma...
CVE-2024-43177CRITICAL9.8IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
CVE-2024-41713CRITICAL9.1A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could...
CVE-2024-40089CRITICAL9.1A Command Injection vulnerability in Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, authenticated attackers to exec...
CVE-2024-40087CRITICAL9.6Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Insecure Permissions. Lack of authentication in the custom TCP ser...
CVE-2024-40086CRITICAL9.6A Buffer Overflow vulnerability in the local_app_set_router_wifi_SSID_PWD function of Vilo 5 Mesh WiFi System <= 5.16.1....
CVE-2024-40085CRITICAL9.6A Buffer Overflow vulnerability in the local_app_set_router_wan function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows ...
CVE-2024-40084CRITICAL9.6A Buffer Overflow in the Boa webserver of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers ...
CVE-2024-40083CRITICAL9.6A Buffer Overflow vulnerabilty in the local_app_set_router_token function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows...
CVE-2024-35314CRITICAL9.8A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instanc...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now