2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-6314CRITICAL9.8The IQ Testimonials plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validatio...
CVE-2024-6313CRITICAL9.8The Gutenberg Forms plugin for WordPress is vulnerable to arbitrary file uploads due to the users can specify the allowe...
CVE-2024-37555CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-p...
CVE-2024-28751CRITICAL9.1An high privileged remote attacker can enable telnet access that accepts hardcoded credentials.
CVE-2024-28747CRITICAL9.8An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privilege...
CVE-2024-5488CRITICAL9.8The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with ano...
CVE-2024-6365CRITICAL9.8The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin...
CVE-2024-1305CRITICAL9.8tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which ...
CVE-2024-39677CRITICAL9.8NHibernate is an object-relational mapper for the .NET framework. A SQL injection vulnerability exists in some types imp...
CVE-2024-39742CRITICAL9.8IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configuration...
CVE-2024-27903CRITICAL9.8OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker ...
CVE-2024-40614CRITICAL9.8EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplat...
CVE-2024-37260CRITICAL9.3Server-Side Request Forgery (SSRF) vulnerability in Theme-Ruby Foxiz.This issue affects Foxiz: from n/a through 2.3.5.
CVE-2024-27712CRITICAL9.8An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile...
CVE-2024-27710CRITICAL9.8An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privile...
CVE-2024-27709CRITICAL9.8SQL Injection vulnerability in Eskooly Web Product v.3.0 allows a remote attacker to execute arbitrary code via the sear...
CVE-2024-37768CRITICAL9.114Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id.
CVE-2024-29319CRITICAL9.8Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. ...
CVE-2024-23998CRITICAL9.6goanother Another Redis Desktop Manager =<1.6.1 is vulnerable to Cross Site Scripting (XSS) via src/components/Setting.v...
CVE-2024-23997CRITICAL9.6Lukas Bach yana =<1.0.16 is vulnerable to Cross Site Scripting (XSS) via src/electron-main.ts.
CVE-2024-39864CRITICAL9.8The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configur...
CVE-2024-39028CRITICAL9.8An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.
CVE-2024-38346CRITICAL9.8The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands...
CVE-2024-6298CRITICAL9.8Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series ...
CVE-2024-39932CRITICAL9.9Gogs through 0.13.0 allows argument injection during the previewing of changes.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now