2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-54092CRITICAL9.8A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device K...
CVE-2024-41794CRITICAL9.8A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). Affected devices contain hardcod...
CVE-2024-58127CRITICAL9.1Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w...
CVE-2024-58126CRITICAL9.1Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w...
CVE-2024-58125CRITICAL9.1Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w...
CVE-2024-58124CRITICAL9.1Access control vulnerability in the security verification module Impact: Successful exploitation of this vulnerability w...
CVE-2024-51800CRITICAL9.8Incorrect Privilege Assignment vulnerability in Favethemes Homey allows Privilege Escalation.This issue affects Homey: f...
CVE-2024-13645CRITICAL9.8The tagDiv Composer plugin for WordPress is vulnerable to PHP Object Instantiation in all versions up to, and including,...
CVE-2024-13744CRITICAL9.8The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida...
CVE-2024-22611CRITICAL9.8OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.cl...
CVE-2024-38392CRITICAL9.1Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remo...
CVE-2024-45064CRITICAL9.8A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZ...
CVE-2024-39780CRITICAL9.8A YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for g...
CVE-2024-13553CRITICAL9.8The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account t...
CVE-2024-56325CRITICAL9.8Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Norm...
CVE-2024-54809CRITICAL9.8Netgear Inc WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the parse_st_header fu...
CVE-2024-54808CRITICAL9.8Netgear WNR854T 1.5.2 (North America) contains a stack-based buffer overflow vulnerability in the SetDefaultConnectionSe...
CVE-2024-54807CRITICAL9.8In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exe...
CVE-2024-54806CRITICAL9.8Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execu...
CVE-2024-54805CRITICAL9.8Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque...
CVE-2024-54804CRITICAL9.8Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque...
CVE-2024-54803CRITICAL9.8Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque...
CVE-2024-54802CRITICAL9.8In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow...
CVE-2024-13804CRITICAL9.8Unauthenticated RCE in HPE Insight Cluster Management Utility
CVE-2024-56975CRITICAL9.8InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerabilit...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now