2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-54803CRITICAL9.8Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted reque...
CVE-2024-54802CRITICAL9.8In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow...
CVE-2024-13804CRITICAL9.8Unauthenticated RCE in HPE Insight Cluster Management Utility
CVE-2024-56975CRITICAL9.8InvoicePlane (all versions tested as of December 2024) v.1.6.11 and before contains a remote code execution vulnerabilit...
CVE-2024-38988CRITICAL9.8alizeait unflatto <= 1.0.2 was discovered to contain a prototype pollution via the method exports.unflatto at /dist/inde...
CVE-2024-38985CRITICAL9.8janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() met...
CVE-2024-24292CRITICAL9.8A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary code via the aim function...
CVE-2024-49601CRITICAL9.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2024-55964CRITICAL9.8An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image lea...
CVE-2024-47516CRITICAL9.8A vulnerability was found in Pagure. An argument injection in Git during retrieval of the repository history leads to re...
CVE-2024-55030CRITICAL9.8A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute ar...
CVE-2024-55028CRITICAL9.8A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via...
CVE-2024-48818CRITICAL9.8An issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to execute arbitrary code.
CVE-2024-42533CRITICAL9.8SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attacker...
CVE-2024-45480CRITICAL9.2An improper control of generation of code ('Code Injection') vulnerability in the AprolCreateReport component of B&R APR...
CVE-2024-53351CRITICAL9.8Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalatio...
CVE-2024-48590CRITICAL9.8Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an...
CVE-2024-9701CRITICAL9.8A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8). This vu...
CVE-2024-9309CRITICAL9.3A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Contro...
CVE-2024-9095CRITICAL9.8In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to...
CVE-2024-9070CRITICAL9.8A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting ...
CVE-2024-9053CRITICAL9.8vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core ...
CVE-2024-8958CRITICAL9.8In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools action...
CVE-2024-8954CRITICAL9.8In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authenticatio...
CVE-2024-8953CRITICAL9.8In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform ma...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now