2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4548 | CRITICAL | 9.8 | 29.4% | May 6, 2024 | An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'Recalcula... |
| CVE-2024-4547 | CRITICAL | 9.8 | 1.9% | May 6, 2024 | A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'Recalculat... |
| CVE-2024-33749 | CRITICAL | 9.1 | 0.6% | May 6, 2024 | DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php. |
| CVE-2024-34524 | CRITICAL | 9.1 | 0.5% | May 6, 2024 | In XLANG OpenAgents through fe73ac4, the allowed_file protection mechanism can be bypassed by using an incorrect file ex... |
| CVE-2024-34502 | CRITICAL | 9.8 | 0.4% | May 5, 2024 | An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Lo... |
| CVE-2024-34461 | CRITICAL | 9.8 | 1.0% | May 4, 2024 | Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY ele... |
| CVE-2024-31673 | CRITICAL | 9.8 | 0.6% | May 3, 2024 | Kliqqi-CMS 2.0.2 is vulnerable to SQL Injection in load_data.php via the userid parameter. |
| CVE-2024-33792 | CRITICAL | 9.8 | 1.0% | May 3, 2024 | netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert pag... |
| CVE-2024-33789 | CRITICAL | 9.8 | 2.4% | May 3, 2024 | Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info... |
| CVE-2024-33786 | CRITICAL | 9.8 | 0.8% | May 3, 2024 | An arbitrary file upload vulnerability in Zhongcheng Kexin Ticketing Management Platform 20.04 allows attackers to execu... |
| CVE-2024-2410 | CRITICAL | 9.8 | 0.3% | May 3, 2024 | The JsonToBinaryStream() function is part of the protocol buffers C++ implementation and is used to parse JSON from a st... |
| CVE-2024-4466 | CRITICAL | 9.8 | 0.5% | May 3, 2024 | SQL injection vulnerability in Gescen on the centrosdigitales.net platform. This vulnerability allows an attacker to sen... |
| CVE-2024-32986 | CRITICAL | 9.6 | 0.7% | May 3, 2024 | PWAsForFirefox is a tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox. Due to improper sani... |
| CVE-2024-33914 | CRITICAL | 9.8 | 0.4% | May 3, 2024 | Missing Authorization vulnerability in Exclusive Addons Exclusive Addons Elementor.This issue affects Exclusive Addons E... |
| CVE-2024-34392 | CRITICAL | 9.8 | 1.1% | May 2, 2024 | libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespa... |
| CVE-2024-34391 | CRITICAL | 9.8 | 1.1% | May 2, 2024 | libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function ... |
| CVE-2024-3729 | CRITICAL | 9.8 | 0.8% | May 2, 2024 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling o... |
| CVE-2024-2876 | CRITICAL | 9.8 | 80.6% | May 2, 2024 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f... |
| CVE-2024-2667 | CRITICAL | 9.8 | 5.7% | May 2, 2024 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to... |
| CVE-2024-1567 | CRITICAL | 9.8 | 1.1% | May 2, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file ... |
| CVE-2024-31967 | CRITICAL | 9.1 | 0.5% | May 2, 2024 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.... |
| CVE-2024-4406 | CRITICAL | 9.6 | 2.2% | May 2, 2024 | Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability ... |
| CVE-2024-4405 | CRITICAL | 9.6 | 1.2% | May 2, 2024 | Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allow... |
| CVE-2024-34144 | CRITICAL | 9.8 | 48.1% | May 2, 2024 | A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_... |
| CVE-2024-23459 | CRITICAL | 9.8 | 0.5% | May 2, 2024 | An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allow... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now