2024 CVE Vulnerabilities

39,241 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-35712MEDIUM4.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jordy Meow Database Clea...
CVE-2024-35680MEDIUM5.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in YITHEMES YITH WooCommerce...
CVE-2024-35677CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes MegaMenu ...
CVE-2024-35658CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeHigh Checkout Field...
CVE-2024-35650HIGH7.2Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-35474MEDIUM6.5A Directory Traversal vulnerability in iceice666 ResourcePack Server before v1.0.8 allows a remote attacker to disclose ...
CVE-2024-34800HIGH7.6Missing Authorization vulnerability in Crafthemes Crafthemes Demo Import crafthemes-demo-import allows Exploiting Incorr...
CVE-2024-34762CRITICAL9.9Vulnerability discovered by executing a planned security audit. Improper Limitation of a Pathname to a Restricted Direc...
CVE-2024-34761HIGH8.5Vulnerability discovered by executing a planned security audit. Improper Control of Generation of Code ('Code Injection...
CVE-2024-34332HIGH7.8An issue in SiSoftware SANDRA v31.66 (SANDRA.sys 15.18.1.1) and before allows an attacker to escalate privileges via a c...
CVE-2024-31613MEDIUM5.4BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code."
CVE-2024-26507HIGH7.8An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit v.7.00.6700 and before allow...
CVE-2024-4403HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability exists in the restart_program function of the parisneo/lollms-webui v9...
CVE-2024-36972HIGH7.8In the Linux kernel, the following vulnerability has been resolved: af_unix: Update unix_sk(sk)->oob_skb under sk_recei...
CVE-2024-36531MEDIUM5.7nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admi...
CVE-2024-36528HIGH8.8nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before have a Deserialization vulnerability which results in co...
CVE-2024-36406MEDIUM5.4SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and ...
CVE-2024-35307CRITICAL9.8Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to e...
CVE-2024-35306CRITICAL9.8OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This...
CVE-2024-35305CRITICAL9.8Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora F...
CVE-2024-35304CRITICAL9.8System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitr...
CVE-2024-5786MEDIUM6.5Cross-Site Request Forgery vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This...
CVE-2024-5785HIGH8Command injection vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerab...
CVE-2024-36405HIGH7.5liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A co...
CVE-2024-3700CRITICAL9.8Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the databas...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now