2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-7575CRITICAL9.8In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through im...
CVE-2024-4657CRITICAL9.3Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Soft...
CVE-2024-6593CRITICAL9.1Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows ...
CVE-2024-6592CRITICAL9.1An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (ak...
CVE-2024-8275CRITICAL9.8The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_...
CVE-2024-8485CRITICAL9.8The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versio...
CVE-2024-9142CRITICAL9.8External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Com...
CVE-2024-8940CRITICAL9.8Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptca...
CVE-2024-8878CRITICAL9.8The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin pa...
CVE-2024-8877CRITICAL9.8Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only li...
CVE-2024-8436CRITICAL9.9The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId...
CVE-2024-46957CRITICAL9.8Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because...
CVE-2024-46612CRITICAL9.8IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication...
CVE-2024-45066CRITICAL9.8A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject a...
CVE-2024-43693CRITICAL9.8A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inj...
CVE-2024-43692CRITICAL9.8An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting t...
CVE-2024-43423CRITICAL9.8The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that...
CVE-2024-42797CRITICAL9.8An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Managem...
CVE-2024-42507CRITICAL9.8Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by s...
CVE-2024-42506CRITICAL9.8Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by s...
CVE-2024-42505CRITICAL9.8Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by s...
CVE-2024-8791CRITICAL9.8The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnera...
CVE-2024-8671CRITICAL9.1The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insuffi...
CVE-2024-8624CRITICAL9.9The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' attrib...
CVE-2024-7024CRITICAL9.6Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perf...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now