2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-57232CRITICAL9.8NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname p...
CVE-2024-57231CRITICAL9.8NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname p...
CVE-2024-57230CRITICAL9.8NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the ifname p...
CVE-2024-57229CRITICAL9.8NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the devname ...
CVE-2024-48905CRITICAL9.1Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.
CVE-2024-32499CRITICAL9.8Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.
CVE-2024-53636CRITICAL9.8An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1....
CVE-2024-30152CRITICAL9.8HCL SX v21 is affected by usage of a weak cryptographic algorithm. An attacker could exploit this weakness to gain acce...
CVE-2024-56156CRITICAL9Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypa...
CVE-2024-40446CRITICAL9.8An issue in forkosh Mime Tex before v.1.77 allows an attacker to execute arbitrary code via a crafted script
CVE-2024-58250CRITICAL9.3The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.
CVE-2024-53591CRITICAL9.8An issue in the login page of Seclore v3.27.5.0 allows attackers to bypass authentication via a brute force attack.
CVE-2024-29643CRITICAL9.1An issue in croogo v.3.0.2 allows an attacker to perform Host header injection via the feed.rss component.
CVE-2024-53924CRITICAL9.8Pycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell,...
CVE-2024-56518CRITICAL9.8Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelc...
CVE-2024-55372CRITICAL9.8Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to ...
CVE-2024-55371CRITICAL9.8Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to res...
CVE-2024-40073CRITICAL9.8Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template p...
CVE-2024-40072CRITICAL9.8Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id paramet...
CVE-2024-40071CRITICAL9.8Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_ge...
CVE-2024-22036CRITICAL9.1A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot jail...
CVE-2024-58136CRITICAL9.8Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regres...
CVE-2024-55210CRITICAL9.8An issue in TOTVS Framework (Linha Protheus) 12.1.2310 allows attackers to bypass multi-factor authentication (MFA) via ...
CVE-2024-12556CRITICAL9.8Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.
CVE-2024-48887CRITICAL9.8A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to c...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now