2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34792HIGH7.2Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in dexta Dextaz Ping a...
CVE-2024-34554HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm ...
CVE-2024-34552HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm ...
CVE-2024-34551CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm ...
CVE-2024-34384HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SinaExtra Sina Extension...
CVE-2024-33628HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in XforWooCommerce allows P...
CVE-2024-33568MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulner...
CVE-2024-36801MEDIUM5.9A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid par...
CVE-2024-36800HIGH7.5A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID param...
CVE-2024-33560CRITICAL9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore allows PHP...
CVE-2024-33557HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allow...
CVE-2024-33541MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BetterAddons Better Elem...
CVE-2024-29170HIGH8.1Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent ...
CVE-2024-25600CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Inj...
CVE-2024-4254HIGH7.1The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable ...
CVE-2024-37065HIGH7.8Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously...
CVE-2024-37064HIGH7.8Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, e...
CVE-2024-37063HIGH7.8A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library all...
CVE-2024-37062HIGH7.8Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, e...
CVE-2024-37061HIGH8.8Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a malicious...
CVE-2024-37060HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling...
CVE-2024-37059HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling ...
CVE-2024-37058HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling ...
CVE-2024-37057HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabli...
CVE-2024-37056HIGH8.8Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now