2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-41874CRITICAL9.8ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that c...
CVE-2024-6656CRITICAL9.8Use of Hard-coded Credentials vulnerability in TNB Mobile Solutions Cockpit Software allows Read Sensitive Strings Withi...
CVE-2024-8762CRITICAL9.8A vulnerability was found in code-projects Crud Operation System 1.0. It has been classified as critical. This affects a...
CVE-2024-7961CRITICAL9.8A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could...
CVE-2024-7960CRITICAL9.1The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive informati...
CVE-2024-8696CRITICAL9.8A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a mal...
CVE-2024-8695CRITICAL9.8A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious e...
CVE-2024-2743CRITICAL9.1An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3....
CVE-2024-45823CRITICAL9.8CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists...
CVE-2024-45824CRITICAL9.8CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chai...
CVE-2024-40457CRITICAL9.1No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: t...
CVE-2024-29847CRITICAL9.8Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows...
CVE-2024-8692CRITICAL9.8A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an ...
CVE-2024-44541CRITICAL9.8evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action...
CVE-2024-44466CRITICAL9.8COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request mes...
CVE-2024-27115CRITICAL9.8A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this ...
CVE-2024-27114CRITICAL9.8A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the pub...
CVE-2024-27113CRITICAL9.8An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that o...
CVE-2024-27112CRITICAL9.8A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabl...
CVE-2024-6091CRITICAL9.8A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist s...
CVE-2024-45790CRITICAL9.8This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authenticati...
CVE-2024-8277CRITICAL9.8The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to,...
CVE-2024-8191CRITICAL9.8SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unau...
CVE-2024-8503CRITICAL9.8An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database reco...
CVE-2024-43040CRITICAL9.1Renwoxing Enterprise Intelligent Management System before v3.0 was discovered to contain a SQL injection vulnerability v...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now