2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-6500CRITICAL10The InPost for WooCommerce plugin and InPost PL plugin for WordPress are vulnerable to unauthorized access and deletion ...
CVE-2024-43042CRITICAL9.8Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.
CVE-2024-42850CRITICAL9.8An issue in the password change function of Silverpeas v6.4.2 and lower allows for the bypassing of password complexity ...
CVE-2024-42639CRITICAL9.8H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as roo...
CVE-2024-42638CRITICAL9.8H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attack...
CVE-2024-42637CRITICAL9.8H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attacker...
CVE-2024-42634CRITICAL9.8A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, ...
CVE-2024-42466CRITICAL9.8Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager a...
CVE-2024-42465CRITICAL9.8Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager a...
CVE-2024-42462CRITICAL9.8Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This i...
CVE-2024-6460CRITICAL9.8The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parame...
CVE-2024-7851CRITICAL9.8A vulnerability has been found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This vul...
CVE-2024-7839CRITICAL9.8A vulnerability classified as critical has been found in itsourcecode Billing System 1.0. This affects an unknown part o...
CVE-2024-43366CRITICAL9.1zkvyper is a Vyper compiler. Starting in version 1.3.12 and prior to version 1.5.3, since LLL IR has no Turing-incomplet...
CVE-2024-7838CRITICAL9.8A vulnerability was found in itsourcecode Online Food Ordering System 1.0. It has been rated as critical. Affected by th...
CVE-2024-42757CRITICAL9.8Command injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via ...
CVE-2024-42472CRITICAL10Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious ...
CVE-2024-27730CRITICAL9.8Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and e...
CVE-2024-23168CRITICAL9.8Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSoc...
CVE-2024-42978CRITICAL9.8An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary co...
CVE-2024-42967CRITICAL9.8Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration fil...
CVE-2024-42966CRITICAL9.8Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration fi...
CVE-2024-42947CRITICAL9.8An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary...
CVE-2024-42843CRITICAL9.8Projectworlds Online Examination System v1.0 is vulnerable to SQL Injection via the subject parameter in feed.php.
CVE-2024-7833CRITICAL9.8A vulnerability was found in D-Link DI-8100 16.07. It has been classified as critical. This affects the function upgrade...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now