2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-5526CRITICAL9.1Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simple...
CVE-2024-4295CRITICAL9.8The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in...
CVE-2024-5262CRITICAL9.8Files or Directories Accessible to External Parties vulnerability in smb server in ProjectDiscovery Interactsh allows re...
CVE-2024-5636CRITICAL9.8A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been rated as critical. Affected by ...
CVE-2024-5635CRITICAL9.8A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been declared as critical. Affected ...
CVE-2024-36675CRITICAL9.1LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.
CVE-2024-36121CRITICAL9.1 netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP r...
CVE-2024-4219CRITICAL9.1Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, ...
CVE-2024-28103CRITICAL9.8Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permis...
CVE-2024-37273CRITICAL9.8An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execut...
CVE-2024-36858CRITICAL9.8An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute...
CVE-2024-36604CRITICAL9.8Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp functio...
CVE-2024-35672CRITICAL9.8Missing Authorization vulnerability in Netgsm.This issue affects Netgsm: from n/a through 2.9.19.
CVE-2024-35670CRITICAL9.8Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/...
CVE-2024-36400CRITICAL9.8nano-id is a unique string ID generator for Rust. Affected versions of the nano-id crate incorrectly generated IDs using...
CVE-2024-35700CRITICAL9.8Incorrect Privilege Assignment vulnerability in DeluxeThemes Userpro userpro.This issue affects Userpro: from n/a throug...
CVE-2024-35629CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-34551CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm ...
CVE-2024-33560CRITICAL9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore allows PHP...
CVE-2024-25600CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Inj...
CVE-2024-4253CRITICAL9.1A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.y...
CVE-2024-36104CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue...
CVE-2024-4180CRITICAL9.1The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering som...
CVE-2024-4552CRITICAL9.8The Social Login Lite For WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and...
CVE-2024-29974CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** The remote code execution vulnerability in the CGI program “file_upload-cgi” in Zyxel NA...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now