2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4371 | CRITICAL | 9.8 | 0.7% | Jun 13, 2024 | The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress... |
| CVE-2024-34107 | CRITICAL | 9.8 | 1.1% | Jun 13, 2024 | Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Access Control vulne... |
| CVE-2024-34102 | CRITICAL | 9.8 | 100.0% | Jun 13, 2024 | Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML E... |
| CVE-2024-26029 | CRITICAL | 9.8 | 0.9% | Jun 13, 2024 | Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Access Control vulnerability that could... |
| CVE-2024-3552 | CRITICAL | 9.8 | 67.3% | Jun 13, 2024 | The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL s... |
| CVE-2024-38295 | CRITICAL | 9.8 | 0.8% | Jun 13, 2024 | ALCASAR before 3.6.1 allows still_connected.php remote code execution. |
| CVE-2024-38294 | CRITICAL | 9.8 | 0.8% | Jun 13, 2024 | ALCASAR before 3.6.1 allows email_registration_back.php remote code execution. |
| CVE-2024-38293 | CRITICAL | 9.6 | 0.4% | Jun 13, 2024 | ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php. |
| CVE-2024-3922 | CRITICAL | 9.8 | 56.2% | Jun 13, 2024 | The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and in... |
| CVE-2024-5898 | CRITICAL | 9.8 | 0.6% | Jun 12, 2024 | A vulnerability was found in itsourcecode Payroll Management System 1.0 and classified as critical. Affected by this iss... |
| CVE-2024-37036 | CRITICAL | 9.8 | 0.5% | Jun 12, 2024 | CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed... |
| CVE-2024-5896 | CRITICAL | 9.8 | 0.7% | Jun 12, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Employee and Visitor Gate Pass Logging Sy... |
| CVE-2024-36761 | CRITICAL | 9.8 | 0.7% | Jun 12, 2024 | naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs. |
| CVE-2024-5895 | CRITICAL | 9.8 | 0.6% | Jun 12, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Employee and Visitor Gate Pass Loggi... |
| CVE-2024-5894 | CRITICAL | 9.8 | 0.6% | Jun 12, 2024 | A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects u... |
| CVE-2024-5893 | CRITICAL | 9.8 | 0.5% | Jun 12, 2024 | A vulnerability classified as critical has been found in SourceCodester Cab Management System 1.0. This affects an unkno... |
| CVE-2024-36840 | CRITICAL | 9.1 | 2.2% | Jun 12, 2024 | SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code a... |
| CVE-2024-36265 | CRITICAL | 9.8 | 0.7% | Jun 12, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affec... |
| CVE-2024-36264 | CRITICAL | 9.8 | 1.0% | Jun 12, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user do... |
| CVE-2024-1659 | CRITICAL | 9.8 | 0.7% | Jun 12, 2024 | Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PH... |
| CVE-2024-1577 | CRITICAL | 9.8 | 1.1% | Jun 12, 2024 | Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring... |
| CVE-2024-1576 | CRITICAL | 9.8 | 0.6% | Jun 12, 2024 | SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including acces... |
| CVE-2024-4898 | CRITICAL | 9.8 | 4.2% | Jun 12, 2024 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due ... |
| CVE-2024-4315 | CRITICAL | 9.1 | 1.0% | Jun 12, 2024 | parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. T... |
| CVE-2024-35213 | CRITICAL | 9 | 0.5% | Jun 11, 2024 | An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now