2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-7012CRITICAL9.8An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to...
CVE-2024-44400CRITICAL9.8A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgr...
CVE-2024-8289CRITICAL9.8The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to privi...
CVE-2024-45507CRITICAL9.8Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OF...
CVE-2024-6926CRITICAL9.8The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQ...
CVE-2024-34657CRITICAL9.8Stack-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows remote attackers to execute arbitrary...
CVE-2024-7950CRITICAL9.8The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to...
CVE-2024-45443CRITICAL9.1Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect a...
CVE-2024-44809CRITICAL9.8A remote code execution (RCE) vulnerability exists in the Pi Camera project, version 1.0, maintained by RECANTHA. The is...
CVE-2024-41433CRITICAL9.8PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList. This...
CVE-2024-45390CRITICAL9.8@blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within...
CVE-2024-45307CRITICAL9.8SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in version...
CVE-2024-7345CRITICAL9.6Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injectio...
CVE-2024-4259CRITICAL9.8Missing Authorization vulnerability in SAMPAŞ Holding AKOS (AkosCepVatandasService), SAMPAŞ Holding AKOS (TahsilatServic...
CVE-2024-8389CRITICAL9.8Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that w...
CVE-2024-8387CRITICAL9.8Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence ...
CVE-2024-8385CRITICAL9.8A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusi...
CVE-2024-8384CRITICAL9.8The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right ...
CVE-2024-8381CRITICAL9.8A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as t...
CVE-2024-44921CRITICAL9.8SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac...
CVE-2024-7261CRITICAL9.8The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware...
CVE-2024-8380CRITICAL9.8A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been rated as critical. This ...
CVE-2024-45623CRITICAL9.8D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer...
CVE-2024-45622CRITICAL9.8ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for A...
CVE-2024-6919CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NAC Telecommunicat...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now