2024 CVE Vulnerabilities
39,242 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34792 | HIGH | 7.2 | 1.1% | Jun 4, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in dexta Dextaz Ping a... |
| CVE-2024-34554 | HIGH | 8.8 | 0.5% | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm ... |
| CVE-2024-34552 | HIGH | 8.8 | 0.5% | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm ... |
| CVE-2024-34551 | CRITICAL | 9.8 | 0.5% | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm ... |
| CVE-2024-34384 | HIGH | 8.8 | 0.6% | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SinaExtra Sina Extension... |
| CVE-2024-33628 | HIGH | 8.8 | 0.6% | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in XforWooCommerce allows P... |
| CVE-2024-33568 | MEDIUM | 6.5 | 0.5% | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulner... |
| CVE-2024-36801 | MEDIUM | 5.9 | 0.4% | Jun 4, 2024 | A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the lgid par... |
| CVE-2024-36800 | HIGH | 7.5 | 0.7% | Jun 4, 2024 | A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID param... |
| CVE-2024-33560 | CRITICAL | 9 | 0.6% | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore allows PHP... |
| CVE-2024-33557 | HIGH | 8.8 | 0.6% | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allow... |
| CVE-2024-33541 | MEDIUM | 6.5 | 0.5% | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BetterAddons Better Elem... |
| CVE-2024-29170 | HIGH | 8.1 | 0.3% | Jun 4, 2024 | Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent ... |
| CVE-2024-25600 | CRITICAL | 10 | 87.5% | Jun 4, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Inj... |
| CVE-2024-4254 | HIGH | 7.1 | 0.5% | Jun 4, 2024 | The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable ... |
| CVE-2024-37065 | HIGH | 7.8 | 0.2% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously... |
| CVE-2024-37064 | HIGH | 7.8 | 0.2% | Jun 4, 2024 | Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, e... |
| CVE-2024-37063 | HIGH | 7.8 | 0.3% | Jun 4, 2024 | A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library all... |
| CVE-2024-37062 | HIGH | 7.8 | 0.2% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, e... |
| CVE-2024-37061 | HIGH | 8.8 | 0.9% | Jun 4, 2024 | Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a malicious... |
| CVE-2024-37060 | HIGH | 8.8 | 0.8% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling... |
| CVE-2024-37059 | HIGH | 8.8 | 0.6% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling ... |
| CVE-2024-37058 | HIGH | 8.8 | 0.6% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling ... |
| CVE-2024-37057 | HIGH | 8.8 | 0.6% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabli... |
| CVE-2024-37056 | HIGH | 8.8 | 0.6% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now