2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-43311CRITICAL9.8Improper Privilege Management vulnerability in Geek Code Lab Login As Users allows Privilege Escalation.This issue affec...
CVE-2024-42815CRITICAL9.8In the TP-Link RE365 V1_180213, there is a buffer overflow vulnerability due to the lack of length verification for the ...
CVE-2024-42813CRITICAL9.8In TRENDnet TEW-752DRU FW1.03B01, there is a buffer overflow vulnerability due to the lack of length verification for th...
CVE-2024-42812CRITICAL9.8In D-Link DIR-860L v2.03, there is a buffer overflow vulnerability due to the lack of length verification for the SID fi...
CVE-2024-43261CRITICAL9.6Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-43252CRITICAL9Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a...
CVE-2024-43248CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bit Apps Bit Form Pro al...
CVE-2024-43245CRITICAL9.8Improper Privilege Management vulnerability in eyecix JobSearch allows Privilege Escalation.This issue affects JobSearch...
CVE-2024-43242CRITICAL10Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue aff...
CVE-2024-43240CRITICAL9.8Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultim...
CVE-2024-42658CRITICAL9.8An issue in wishnet Nepstech Wifi Router NTPL-XPON1GFEVN v1.0 allows a remote attacker to obtain sensitive information v...
CVE-2024-37099CRITICAL9.8Deserialization of Untrusted Data vulnerability in Liquid Web GiveWP allows Object Injection.This issue affects GiveWP: ...
CVE-2024-7922CRITICAL9.8A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-32...
CVE-2024-43399CRITICAL9.8Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor...
CVE-2024-6330CRITICAL9.8The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files ...
CVE-2024-7921CRITICAL9.8A vulnerability has been found in Anhui Deshun Intelligent Technology Jieshun JieLink+ JSOTC2016 up to 20240805 and clas...
CVE-2024-44076CRITICAL9.8In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.
CVE-2024-7920CRITICAL9.8A vulnerability, which was classified as problematic, was found in Anhui Deshun Intelligent Technology Jieshun JieLink+ ...
CVE-2024-7919CRITICAL9.8A vulnerability, which was classified as critical, has been found in Anhui Deshun Intelligent Technology Jieshun JieLink...
CVE-2024-7913CRITICAL9.8A vulnerability was found in itsourcecode Billing System 1.0. It has been rated as critical. This issue affects some unk...
CVE-2024-43322CRITICAL9.8Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects ...
CVE-2024-7911CRITICAL9.8A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. This a...
CVE-2024-7909CRITICAL9.8A vulnerability has been found in TOTOLINK EX1200L 9.3.5u.6146_B20201023 and classified as critical. Affected by this vu...
CVE-2024-7908CRITICAL9.8A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected is the ...
CVE-2024-7907CRITICAL9.8A vulnerability, which was classified as critical, has been found in TOTOLINK X6000R 9.4.0cu.852_20230719. This issue af...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now