2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-9921CRITICAL9.8The Team+ from TEAMPLUS TECHNOLOGY does not properly validate specific page parameter, allowing unauthenticated remote a...
CVE-2024-7099CRITICAL9.8netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenat...
CVE-2024-9916CRITICAL9.8A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some u...
CVE-2024-9047CRITICAL9.8The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.2...
CVE-2024-48772CRITICAL9.1An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firm...
CVE-2024-48787CRITICAL9.1An issue in Revic Optics Revic Ops (us.revic.revicops) 1.12.5 allows a remote attacker to obtain sensitive information v...
CVE-2024-48786CRITICAL9.1An issue in SWITCHBOT INC SwitchBot (com.theswitchbot.switchbot) 5.0.4 allows a remote attacker to obtain sensitive info...
CVE-2024-48784CRITICAL9.8An Incorrect Access Control issue in SAMPMAX com.sampmax.homemax 2.1.2.7 allows a remote attacker to obtain sensitive in...
CVE-2024-48778CRITICAL9.1An issue in GIANT MANUFACTURING CO., LTD RideLink (tw.giant.ridelink) 2.0.7 allows a remote attacker to obtain sensitive...
CVE-2024-48769CRITICAL9.1An issue in BURG-WCHTER KG de.burgwachter.keyapp.app 4.5.0 allows a remote attacker to obtain sensitve information via t...
CVE-2024-48033CRITICAL9.8Deserialization of Untrusted Data vulnerability in baptiste.gourdin Talkback talkback-secure-linkback-protocol allows Ob...
CVE-2024-47331CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ninja Team Multi S...
CVE-2024-46532CRITICAL9.8SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the...
CVE-2024-46088CRITICAL9.8An arbitrary file upload vulnerability in the ProductAction.entphone interface of Zhejiang University Entersoft Customer...
CVE-2024-44730CRITICAL9.1Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows atta...
CVE-2024-42640CRITICAL9.8angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Explo...
CVE-2024-8755CRITICAL9.8Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This ...
CVE-2024-47074CRITICAL9.8DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source ...
CVE-2024-45402CRITICAL9.8Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. When parsi...
CVE-2024-9707CRITICAL9.8The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing ca...
CVE-2024-9234CRITICAL9.8The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerabl...
CVE-2024-21534CRITICAL9.8All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitizati...
CVE-2024-9822CRITICAL9.8The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5...
CVE-2024-9818CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Online Veterinary Appointment System 1.0. Affect...
CVE-2024-47871CRITICAL9.1Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **insecure communica...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now