2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-34399CRITICAL9.8**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker ...
CVE-2024-6878CRITICAL9.2Files or Directories Accessible to External Parties vulnerability in Eliz Software Panel allows Collect Data from Common...
CVE-2024-5960CRITICAL9.8Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials. This iss...
CVE-2024-44542CRITICAL9.8SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news....
CVE-2024-35515CRITICAL9.8Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.
CVE-2024-34026CRITICAL9.8A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v...
CVE-2024-8892CRITICAL9.1Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value...
CVE-2024-8889CRITICAL9.1Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value...
CVE-2024-44004CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arni Cinco WPCargo...
CVE-2024-43978CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super S...
CVE-2024-43976CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super S...
CVE-2024-8956CRITICAL9.1PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does...
CVE-2024-45798CRITICAL9.9arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Th...
CVE-2024-38183CRITICAL9.8An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a ne...
CVE-2024-8944CRITICAL9.8A vulnerability, which was classified as critical, was found in code-projects Hospital Management System 1.0. This affec...
CVE-2024-45682CRITICAL9.8There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operatin...
CVE-2024-38813CRITICAL9.8The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Serve...
CVE-2024-38812CRITICAL9.8The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious acto...
CVE-2024-7873CRITICAL9.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escapi...
CVE-2024-8767CRITICAL9.9Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected...
CVE-2024-7387CRITICAL9.1A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious...
CVE-2024-45496CRITICAL9.9A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Pla...
CVE-2024-44148CRITICAL10This issue was addressed with improved validation of file attributes. This issue is fixed in macOS Sequoia 15. An app ma...
CVE-2024-44146CRITICAL10A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15. An app may be able to ...
CVE-2024-45415CRITICAL9.8The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity functio...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now