2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7425HIGH7.2The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege...
CVE-2024-9664HIGH7.2The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4...
CVE-2024-9661MEDIUM4.3The WP All Import Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2024-7419HIGH8.8The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, ...
CVE-2024-57707CRITICAL9.8An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and password components.
CVE-2024-57249MEDIUM6.5Incorrect Access Control in the Preview Function of Gleamtech FileVista 9.2.0.0 allows remote attackers to gain unauthor...
CVE-2024-57248MEDIUM6.3Directory Traversal in File Upload in Gleamtech FileVista 9.2.0.0 allows remote attackers to achieve Code Execution, Inf...
CVE-2024-55214MEDIUM6.5Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive informatio...
CVE-2024-55213MEDIUM6.5Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information...
CVE-2024-52884HIGH7.5An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of we...
CVE-2024-52883HIGH7.5An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnera...
CVE-2024-52882MEDIUM6.1An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization ...
CVE-2024-52881HIGH7.5An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded ...
CVE-2024-48091HIGH7.8Tally Prime Edit Log v2.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. Thi...
CVE-2024-35106MEDIUM4.6NEXTU FLETA AX1500 WIFI6 v1.0.3 was discovered to contain a buffer overflow at /boafrm/formIpQoS. This vulnerability all...
CVE-2024-10383MEDIUM6.1An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions pri...
CVE-2024-13841MEDIUM4.3The Builder Shortcode Extras – WordPress Shortcodes Collection to Save You Time plugin for WordPress is vulnerable to In...
CVE-2024-13492MEDIUM6.1The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back...
CVE-2024-13352HIGH7.1The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page...
CVE-2024-57609HIGH8.6An issue in Kanaries Inc Pygwalker before v.0.4.9.9 allows a remote attacker to obtain sensitive information and execute...
CVE-2024-57392HIGH7.5Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can caus...
CVE-2024-56889HIGH7.5Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauth...
CVE-2024-55241HIGH8.8An issue in deep-diver LLM-As-Chatbot before commit 99c2c03 allows a remote attacker to execute arbitrary code via the m...
CVE-2024-54909HIGH8.1A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/...
CVE-2024-53586MEDIUM5.3An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a cra...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now