2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-47901CRITICAL9.8A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fir...
CVE-2024-47575CRITICAL9.8A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2...
CVE-2024-10279CRITICAL9.8A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. This vulnerability affects unknown code o...
CVE-2024-10278CRITICAL9.8A vulnerability was found in ESAFENET CDG 5. It has been classified as critical. This affects an unknown part of the fil...
CVE-2024-10277CRITICAL9.8A vulnerability was found in ESAFENET CDG 5 and classified as critical. Affected by this issue is some unknown functiona...
CVE-2024-43924CRITICAL9.8Missing Authorization vulnerability in dFactory Responsive Lightbox allows Accessing Functionality Not Properly Constrai...
CVE-2024-9947CRITICAL9.8The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4...
CVE-2024-46483CRITICAL9.8Xlight FTP Server <3.9.4.3 has an integer overflow vulnerability in the packet parsing logic of the SFTP server, which c...
CVE-2024-44812CRITICAL9.8SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the usern...
CVE-2024-43698CRITICAL9.8Kieback & Peter's DDC4000 series uses weak credentials, which may allow an unauthenticated attacker to get full admin ri...
CVE-2024-41717CRITICAL9.8Kieback & Peter's DDC4000 series is vulnerable to a path traversal vulnerability, which may allow an unauthenticated att...
CVE-2024-40494CRITICAL9.8Buffer Overflow in coap_msg.c in FreeCoAP allows remote attackers to execute arbitrary code or cause a denial of service...
CVE-2024-40493CRITICAL9.8Null Pointer Dereference in `coap_client_exchange_blockwise2` function in Keith Cullen FreeCoAP 1.0 allows remote attack...
CVE-2024-26519CRITICAL9An issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a cr...
CVE-2024-48919CRITICAL9.2Cursor is a code editor built for programming with AI. Prior to Sep 27, 2024, if a user generated a terminal command via...
CVE-2024-48904CRITICAL9.8An command injection vulnerability in Trend Micro Cloud Edge could allow a remote attacker to execute arbitrary code on ...
CVE-2024-46902CRITICAL9.1A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose...
CVE-2024-9129CRITICAL9.3In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered. Reported by Dylan Ma...
CVE-2024-43177CRITICAL9.8IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
CVE-2024-41713CRITICAL9.1A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could...
CVE-2024-40089CRITICAL9.1A Command Injection vulnerability in Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, authenticated attackers to exec...
CVE-2024-40087CRITICAL9.6Vilo 5 Mesh WiFi System <= 5.16.1.33 is vulnerable to Insecure Permissions. Lack of authentication in the custom TCP ser...
CVE-2024-40086CRITICAL9.6A Buffer Overflow vulnerability in the local_app_set_router_wifi_SSID_PWD function of Vilo 5 Mesh WiFi System <= 5.16.1....
CVE-2024-40085CRITICAL9.6A Buffer Overflow vulnerability in the local_app_set_router_wan function of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows ...
CVE-2024-40084CRITICAL9.6A Buffer Overflow in the Boa webserver of Vilo 5 Mesh WiFi System <= 5.16.1.33 allows remote, unauthenticated attackers ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now