2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-9814CRITICAL9.8A vulnerability, which was classified as critical, was found in Codezips Pharmacy Management System 1.0. Affected is an ...
CVE-2024-9487CRITICAL9.1An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowe...
CVE-2024-47167CRITICAL9.8Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **Server-Side Requ...
CVE-2024-9813CRITICAL9.8A vulnerability, which was classified as critical, has been found in Codezips Pharmacy Management System 1.0. This issue...
CVE-2024-9812CRITICAL9.8A vulnerability classified as critical was found in code-projects Crud Operation System 1.0. This vulnerability affects ...
CVE-2024-9811CRITICAL9.8A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. This affects a...
CVE-2024-47636CRITICAL9.8Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch allows Object Injection.This issue affe...
CVE-2024-9794CRITICAL9.8A vulnerability, which was classified as critical, has been found in Codezips Online Shopping Portal 1.0. This issue aff...
CVE-2024-9793CRITICAL9.8A vulnerability classified as critical was found in Tenda AC1206 up to 15.03.06.23. This vulnerability affects the funct...
CVE-2024-9201CRITICAL9.8The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQL injection through the use of the ‘id_o...
CVE-2024-45115CRITICAL9.8Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication v...
CVE-2024-9796CRITICAL9.8The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a...
CVE-2024-9518CRITICAL9.8The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to ins...
CVE-2024-48949CRITICAL9.1The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(s...
CVE-2024-47832CRITICAL9.8ssoready is a single sign on provider implemented via docker. Affected versions are vulnerable to XML signature bypass a...
CVE-2024-9465CRITICAL9.1An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition ...
CVE-2024-45746CRITICAL9.8An issue was discovered in Trusted Firmware-M through 2.1.0. User provided (and controlled) mailbox messages contain a p...
CVE-2024-25825CRITICAL9.8FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be ...
CVE-2024-9680CRITICAL9.8An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timeli...
CVE-2024-45160CRITICAL9.1Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 clien...
CVE-2024-32608CRITICAL9.8HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer a...
CVE-2024-47823CRITICAL9.8Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/li...
CVE-2024-43591CRITICAL9.1Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability
CVE-2024-43488CRITICAL9.8Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attac...
CVE-2024-43468CRITICAL9.8Microsoft Configuration Manager Remote Code Execution Vulnerability

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now