2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-31231CRITICAL9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sizam Design Rehub allow...
CVE-2024-30542CRITICAL9.8Improper Privilege Management vulnerability in Wholesale WholesaleX allows Privilege Escalation.This issue affects Whole...
CVE-2024-27954CRITICAL9.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic a...
CVE-2024-24882CRITICAL9.8Incorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects ...
CVE-2024-22157CRITICAL9.8Improper Privilege Management vulnerability in WebWizards SalesKing allows Privilege Escalation.This issue affects Sales...
CVE-2024-33556CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from...
CVE-2024-31351CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Copymatic Copymatic – AI Content Writer & Generator.Thi...
CVE-2024-3551CRITICAL9.8The Penci Soledad Data Migrator plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in...
CVE-2024-22476CRITICAL10Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated ...
CVE-2024-5023CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Netflix ConsoleMe a...
CVE-2024-4609CRITICAL9.8A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor ...
CVE-2024-35187CRITICAL9.1Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execut...
CVE-2024-4999CRITICAL9.4A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote a...
CVE-2024-4992CRITICAL9.8Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_kuliah/aksi_kuliah.php parameter in nim. This ...
CVE-2024-4991CRITICAL9.8Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_pass/aksi_pass.php parameter in nama_lengkap. ...
CVE-2024-4826CRITICAL9.8SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacke...
CVE-2024-4973CRITICAL9.8A vulnerability classified as critical was found in code-projects Simple Chat System 1.0. This vulnerability affects unk...
CVE-2024-4972CRITICAL9.8A vulnerability classified as critical has been found in code-projects Simple Chat System 1.0. This affects an unknown p...
CVE-2024-4967CRITICAL9.8A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been declared as critical. Affected ...
CVE-2024-4326CRITICAL9.8A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulne...
CVE-2024-4223CRITICAL9.8The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due ...
CVE-2024-4078CRITICAL9.8A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code exe...
CVE-2024-2366CRITICAL9A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall...
CVE-2024-2361CRITICAL9.6A vulnerability in the parisneo/lollms-webui allows for arbitrary file upload and read due to insufficient sanitization ...
CVE-2024-2358CRITICAL9.8A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute ar...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now