2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-34048CRITICAL9.8O-RAN RIC I-Release e2mgr lacks array size checks in E2nodeConfigUpdateNotificationHandler.
CVE-2024-33350CRITICAL9.8Directory Traversal vulnerability in TaoCMS v.3.0.2 allows a remote attacker to execute arbitrary code and obtain sensit...
CVE-2024-33435CRITICAL9.8Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intellig...
CVE-2024-33276CRITICAL9.8SQL Injection vulnerability in FME Modules preorderandnotication v.3.1.0 and before allows a remote attacker to run arbi...
CVE-2024-33269CRITICAL9.8SQL Injection vulnerability in Prestaddons flashsales 1.9.7 and before allows an attacker to run arbitrary SQL commands ...
CVE-2024-33268CRITICAL9.8SQL Injection vulnerability in Digincube mdgiftproduct before 1.4.1 allows an attacker to run arbitrary SQL commands via...
CVE-2024-33266CRITICAL9.8SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary ...
CVE-2024-31823CRITICAL9.8An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker ...
CVE-2024-31822CRITICAL9.8An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker ...
CVE-2024-31820CRITICAL9.8An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker ...
CVE-2024-31705CRITICAL9.8An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insuffici...
CVE-2024-33449CRITICAL9.8An SSRF issue in the PDFMyURL service allows a remote attacker to obtain sensitive information and execute arbitrary cod...
CVE-2024-33445CRITICAL9.8An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugin...
CVE-2024-33444CRITICAL9.8SQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to th...
CVE-2024-32491CRITICAL9.8An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in use...
CVE-2024-3375CRITICAL9.4Incorrect Permission Assignment for Critical Resource vulnerability in Havelsan Inc. Dialogue allows Accessing Functiona...
CVE-2024-33566CRITICAL10Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: fro...
CVE-2024-33553CRITICAL9.8Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5...
CVE-2024-3192CRITICAL9.6A vulnerability, which was classified as problematic, was found in MailCleaner up to 2023.03.14. Affected is an unknown ...
CVE-2024-3191CRITICAL9.8A vulnerability, which was classified as critical, has been found in MailCleaner up to 2023.03.14. This issue affects so...
CVE-2024-33546CRITICAL9.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allo...
CVE-2024-33544CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allo...
CVE-2024-33559CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allo...
CVE-2024-33551CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core...
CVE-2024-4300CRITICAL9.8E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the data...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now