2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-46986CRITICAL9.9Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnera...
CVE-2024-45523CRITICAL9.1An issue was discovered in Bravura Security Fabric versions 12.3.x before 12.3.5.32784, 12.4.x before 12.4.3.35110, 12.5...
CVE-2024-34399CRITICAL9.8**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker ...
CVE-2024-6878CRITICAL9.2Files or Directories Accessible to External Parties vulnerability in Eliz Software Panel allows Collect Data from Common...
CVE-2024-5960CRITICAL9.8Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials. This iss...
CVE-2024-44542CRITICAL9.8SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news....
CVE-2024-35515CRITICAL9.8Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.
CVE-2024-34026CRITICAL9.8A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v...
CVE-2024-8892CRITICAL9.1Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value...
CVE-2024-8889CRITICAL9.1Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value...
CVE-2024-44004CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo...
CVE-2024-43978CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super S...
CVE-2024-43976CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super S...
CVE-2024-8956CRITICAL9.1PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does...
CVE-2024-45798CRITICAL9.9arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Th...
CVE-2024-38183CRITICAL9.8An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a ne...
CVE-2024-8944CRITICAL9.8A vulnerability, which was classified as critical, was found in code-projects Hospital Management System 1.0. This affec...
CVE-2024-45682CRITICAL9.8There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operatin...
CVE-2024-38813CRITICAL9.8The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Serve...
CVE-2024-38812CRITICAL9.8The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious acto...
CVE-2024-7873CRITICAL9.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escapi...
CVE-2024-8767CRITICAL9.9Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected...
CVE-2024-7387CRITICAL9.1A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious...
CVE-2024-45496CRITICAL9.9A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Pla...
CVE-2024-44148CRITICAL10This issue was addressed with improved validation of file attributes. This issue is fixed in macOS Sequoia 15. An app ma...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now