2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31231 | CRITICAL | 9 | 0.6% | May 17, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sizam Design Rehub allow... |
| CVE-2024-30542 | CRITICAL | 9.8 | 0.5% | May 17, 2024 | Improper Privilege Management vulnerability in Wholesale WholesaleX allows Privilege Escalation.This issue affects Whole... |
| CVE-2024-27954 | CRITICAL | 9.3 | 73.0% | May 17, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic a... |
| CVE-2024-24882 | CRITICAL | 9.8 | 2.1% | May 17, 2024 | Incorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects ... |
| CVE-2024-22157 | CRITICAL | 9.8 | 0.6% | May 17, 2024 | Improper Privilege Management vulnerability in WebWizards SalesKing allows Privilege Escalation.This issue affects Sales... |
| CVE-2024-33556 | CRITICAL | 9.8 | 0.6% | May 17, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in 8theme XStore Core.This issue affects XStore Core: from... |
| CVE-2024-31351 | CRITICAL | 9.8 | 1.6% | May 17, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Copymatic Copymatic – AI Content Writer & Generator.Thi... |
| CVE-2024-3551 | CRITICAL | 9.8 | 0.7% | May 17, 2024 | The Penci Soledad Data Migrator plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in... |
| CVE-2024-22476 | CRITICAL | 10 | 33.4% | May 16, 2024 | Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated ... |
| CVE-2024-5023 | CRITICAL | 9.3 | 0.9% | May 16, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Netflix ConsoleMe a... |
| CVE-2024-4609 | CRITICAL | 9.8 | 0.7% | May 16, 2024 | A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor ... |
| CVE-2024-35187 | CRITICAL | 9.1 | 0.7% | May 16, 2024 | Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execut... |
| CVE-2024-4999 | CRITICAL | 9.4 | 12.2% | May 16, 2024 | A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote a... |
| CVE-2024-4992 | CRITICAL | 9.8 | 0.5% | May 16, 2024 | Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_kuliah/aksi_kuliah.php parameter in nim. This ... |
| CVE-2024-4991 | CRITICAL | 9.8 | 0.5% | May 16, 2024 | Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_pass/aksi_pass.php parameter in nama_lengkap. ... |
| CVE-2024-4826 | CRITICAL | 9.8 | 0.4% | May 16, 2024 | SQL injection vulnerability in Simple PHP Shopping Cart affecting version 0.9. This vulnerability could allow an attacke... |
| CVE-2024-4973 | CRITICAL | 9.8 | 0.6% | May 16, 2024 | A vulnerability classified as critical was found in code-projects Simple Chat System 1.0. This vulnerability affects unk... |
| CVE-2024-4972 | CRITICAL | 9.8 | 0.6% | May 16, 2024 | A vulnerability classified as critical has been found in code-projects Simple Chat System 1.0. This affects an unknown p... |
| CVE-2024-4967 | CRITICAL | 9.8 | 0.6% | May 16, 2024 | A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been declared as critical. Affected ... |
| CVE-2024-4326 | CRITICAL | 9.8 | 1.0% | May 16, 2024 | A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulne... |
| CVE-2024-4223 | CRITICAL | 9.8 | 0.5% | May 16, 2024 | The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due ... |
| CVE-2024-4078 | CRITICAL | 9.8 | 0.9% | May 16, 2024 | A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code exe... |
| CVE-2024-2366 | CRITICAL | 9 | 0.7% | May 16, 2024 | A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall... |
| CVE-2024-2361 | CRITICAL | 9.6 | 0.6% | May 16, 2024 | A vulnerability in the parisneo/lollms-webui allows for arbitrary file upload and read due to insufficient sanitization ... |
| CVE-2024-2358 | CRITICAL | 9.8 | 1.1% | May 16, 2024 | A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute ar... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now