2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-48914CRITICAL9.1Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's as...
CVE-2024-9986CRITICAL9.8A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue a...
CVE-2024-48283CRITICAL9.8Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-res...
CVE-2024-9976CRITICAL9.8A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an u...
CVE-2024-49388CRITICAL9.1Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Pro...
CVE-2024-45275CRITICAL9.8The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker ...
CVE-2024-45274CRITICAL9.8An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.
CVE-2024-9974CRITICAL9.8A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this ...
CVE-2024-9973CRITICAL9.8A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. Affected is an ...
CVE-2024-47945CRITICAL9.8The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The...
CVE-2024-9985CRITICAL9.8Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privil...
CVE-2024-9984CRITICAL9.8Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated re...
CVE-2024-9925CRITICAL9.8SQL injection vulnerability in TAI Smart Factory's QPLANT SF version 1.0. Exploitation of this vulnerability could allow...
CVE-2024-47943CRITICAL9.8The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices c...
CVE-2024-9982CRITICAL9.8AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Cam...
CVE-2024-9972CRITICAL9.8Property Management System from ChanGate has a SQL Injection vulnerability, allowing unauthenticated remote attackers to...
CVE-2024-48823CRITICAL9.8Local file inclusion in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a r...
CVE-2024-48168CRITICAL9.8A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing a...
CVE-2024-46535CRITICAL9.8Jepaas v7.2.8 was discovered to contain a SQL injection vulnerability via the orderSQL parameter at /homePortal/loadUser...
CVE-2024-48153CRITICAL9.8DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary comm...
CVE-2024-48150CRITICAL9.8D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.
CVE-2024-48257CRITICAL9.8Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.
CVE-2024-48251CRITICAL9.8Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.
CVE-2024-48255CRITICAL9.8Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.
CVE-2024-48253CRITICAL9.8Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now