2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-4548CRITICAL9.8An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'Recalcula...
CVE-2024-4547CRITICAL9.8A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'Recalculat...
CVE-2024-33749CRITICAL9.1DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.
CVE-2024-34524CRITICAL9.1In XLANG OpenAgents through fe73ac4, the allowed_file protection mechanism can be bypassed by using an incorrect file ex...
CVE-2024-34502CRITICAL9.8An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Lo...
CVE-2024-34461CRITICAL9.8Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY ele...
CVE-2024-31673CRITICAL9.8Kliqqi-CMS 2.0.2 is vulnerable to SQL Injection in load_data.php via the userid parameter.
CVE-2024-33792CRITICAL9.8netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert pag...
CVE-2024-33789CRITICAL9.8Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info...
CVE-2024-33786CRITICAL9.8An arbitrary file upload vulnerability in Zhongcheng Kexin Ticketing Management Platform 20.04 allows attackers to execu...
CVE-2024-2410CRITICAL9.8The JsonToBinaryStream() function is part of the protocol buffers C++ implementation and is used to parse JSON from a st...
CVE-2024-4466CRITICAL9.8SQL injection vulnerability in Gescen on the centrosdigitales.net platform. This vulnerability allows an attacker to sen...
CVE-2024-32986CRITICAL9.6PWAsForFirefox is a tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox. Due to improper sani...
CVE-2024-33914CRITICAL9.8Missing Authorization vulnerability in Exclusive Addons Exclusive Addons Elementor.This issue affects Exclusive Addons E...
CVE-2024-34392CRITICAL9.8libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking the namespa...
CVE-2024-34391CRITICAL9.8libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function ...
CVE-2024-3729CRITICAL9.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to improper missing encryption exception handling o...
CVE-2024-2876CRITICAL9.8The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f...
CVE-2024-2667CRITICAL9.8The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to...
CVE-2024-1567CRITICAL9.8The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file ...
CVE-2024-31967CRITICAL9.1A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3....
CVE-2024-4406CRITICAL9.6Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability ...
CVE-2024-4405CRITICAL9.6Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allow...
CVE-2024-34144CRITICAL9.8A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_...
CVE-2024-23459CRITICAL9.8An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allow...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now