2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-45771CRITICAL9.8RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin...
CVE-2024-44839CRITICAL9.8RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article....
CVE-2024-44838CRITICAL9.8RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin...
CVE-2024-8517CRITICAL9.8SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacke...
CVE-2024-45758CRITICAL9.1H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file r...
CVE-2024-44402CRITICAL9.8D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.
CVE-2024-44401CRITICAL9.8D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file
CVE-2024-7493CRITICAL9.8The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2....
CVE-2024-8292CRITICAL9.8The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/accoun...
CVE-2024-8395CRITICAL9.8FlyCASS CASS and KCM systems did not correctly filter SQL queries, which made them vulnerable to attack by outside atta...
CVE-2024-45159CRITICAL9.8An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the...
CVE-2024-45158CRITICAL9.8An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_...
CVE-2024-44727CRITICAL9.8Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/lo...
CVE-2024-24759CRITICAL9.1MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat ac...
CVE-2024-42885CRITICAL9.1SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id param...
CVE-2024-43102CRITICAL10Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM...
CVE-2024-8416CRITICAL9.8A vulnerability was found in SourceCodester Food Ordering Management System 1.0. It has been classified as critical. Thi...
CVE-2024-8415CRITICAL9.8A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as critical. Affected by ...
CVE-2024-20439CRITICAL9.8A vulnerability in Cisco Smart Licensing Utility (CSLU) could allow an unauthenticated, remote attacker to log into an a...
CVE-2024-45076CRITICAL9.9IBM webMethods Integration 10.15 could allow an authenticated user to upload and execute arbitrary files which could be ...
CVE-2024-44808CRITICAL9.8An issue in Vypor Attack API System v.1.0 allows a remote attacker to execute arbitrary code via the user GET parameter.
CVE-2024-7078CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics...
CVE-2024-7076CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Semtek Informatics...
CVE-2024-8408CRITICAL9.8A vulnerability was found in Linksys WRT54G 4.21.5. It has been rated as critical. Affected by this issue is the functio...
CVE-2024-7923CRITICAL9.8An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now