2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-48283CRITICAL9.8Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-res...
CVE-2024-9976CRITICAL9.8A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an u...
CVE-2024-49388CRITICAL9.1Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Pro...
CVE-2024-45275CRITICAL9.8The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker ...
CVE-2024-45274CRITICAL9.8An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
CVE-2024-9974CRITICAL9.8A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this ...
CVE-2024-9973CRITICAL9.8A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. Affected is an ...
CVE-2024-47945CRITICAL9.8The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The...
CVE-2024-9985CRITICAL9.8Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privil...
CVE-2024-9984CRITICAL9.8Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated re...
CVE-2024-9925CRITICAL9.8SQL injection vulnerability in TAI Smart Factory's QPLANT SF version 1.0. Exploitation of this vulnerability could allow...
CVE-2024-47943CRITICAL9.8The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices c...
CVE-2024-9982CRITICAL9.8AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Cam...
CVE-2024-9972CRITICAL9.8Property Management System from ChanGate has a SQL Injection vulnerability, allowing unauthenticated remote attackers to...
CVE-2024-48823CRITICAL9.8Local file inclusion in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a r...
CVE-2024-48168CRITICAL9.8A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing a...
CVE-2024-46535CRITICAL9.8Jepaas v7.2.8 was discovered to contain a SQL injection vulnerability via the orderSQL parameter at /homePortal/loadUser...
CVE-2024-48153CRITICAL9.8DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm...
CVE-2024-48150CRITICAL9.8D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.
CVE-2024-48257CRITICAL9.8Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.
CVE-2024-48251CRITICAL9.8Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.
CVE-2024-48255CRITICAL9.8Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.
CVE-2024-48253CRITICAL9.8Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.
CVE-2024-9137CRITICAL9.4The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulner...
CVE-2024-9924CRITICAL9.8The fix for CVE-2024-26261 was incomplete, and and the specific package for OAKlouds from Hgiga remains at risk. Unauthe...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now