2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-38124CRITICAL9Windows Netlogon Elevation of Privilege Vulnerability
CVE-2024-47010CRITICAL9.8Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authenticatio...
CVE-2024-47009CRITICAL9.8Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authenticatio...
CVE-2024-45918CRITICAL9.8Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_g...
CVE-2024-44349CRITICAL9.8A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute ar...
CVE-2024-3057CRITICAL9.8A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation.
CVE-2024-8884CRITICAL9.8CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of cr...
CVE-2024-8943CRITICAL9.8The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. Thi...
CVE-2024-8911CRITICAL9.8The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, ...
CVE-2024-47553CRITICAL9.9A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not...
CVE-2024-41798CRITICAL9.8A vulnerability has been identified in SENTRON 7KM PAC3200 (All versions). Affected devices only provide a 4-digit PIN t...
CVE-2024-45874CRITICAL9.8A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence ...
CVE-2024-45873CRITICAL9.8A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persisten...
CVE-2024-47557CRITICAL9.8Pre-Auth RCE via Path Traversal
CVE-2024-47556CRITICAL9.8Pre-Auth RCE via Path Traversal
CVE-2024-46076CRITICAL9.8RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabl...
CVE-2024-46446CRITICAL9.8Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identi...
CVE-2024-33066CRITICAL9.8Memory corruption while redirecting log file to any file location with any file name.
CVE-2024-20103CRITICAL9.8In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote co...
CVE-2024-20101CRITICAL9.8In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code...
CVE-2024-20100CRITICAL9.8In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code...
CVE-2024-47350CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITHEMES YITH WooC...
CVE-2024-45252CRITICAL9.8Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-45251CRITICAL9.8Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-45249CRITICAL9.8Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now