2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-4371CRITICAL9.8The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress...
CVE-2024-34107CRITICAL9.8Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Access Control vulne...
CVE-2024-34102CRITICAL9.8Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML E...
CVE-2024-26029CRITICAL9.8Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Access Control vulnerability that could...
CVE-2024-3552CRITICAL9.8The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL s...
CVE-2024-38295CRITICAL9.8ALCASAR before 3.6.1 allows still_connected.php remote code execution.
CVE-2024-38294CRITICAL9.8ALCASAR before 3.6.1 allows email_registration_back.php remote code execution.
CVE-2024-38293CRITICAL9.6ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php.
CVE-2024-3922CRITICAL9.8The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and in...
CVE-2024-5898CRITICAL9.8A vulnerability was found in itsourcecode Payroll Management System 1.0 and classified as critical. Affected by this iss...
CVE-2024-37036CRITICAL9.8CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed...
CVE-2024-5896CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Employee and Visitor Gate Pass Logging Sy...
CVE-2024-36761CRITICAL9.8naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.
CVE-2024-5895CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Loggi...
CVE-2024-5894CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects u...
CVE-2024-5893CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Cab Management System 1.0. This affects an unkno...
CVE-2024-36840CRITICAL9.1SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code a...
CVE-2024-36265CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affec...
CVE-2024-36264CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user do...
CVE-2024-1659CRITICAL9.8Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PH...
CVE-2024-1577CRITICAL9.8Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring...
CVE-2024-1576CRITICAL9.8SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including acces...
CVE-2024-4898CRITICAL9.8The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due ...
CVE-2024-4315CRITICAL9.1parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. T...
CVE-2024-35213CRITICAL9An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now