2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33276 | CRITICAL | 9.8 | 0.6% | Apr 29, 2024 | SQL Injection vulnerability in FME Modules preorderandnotication v.3.1.0 and before allows a remote attacker to run arbi... |
| CVE-2024-33269 | CRITICAL | 9.8 | 0.5% | Apr 29, 2024 | SQL Injection vulnerability in Prestaddons flashsales 1.9.7 and before allows an attacker to run arbitrary SQL commands ... |
| CVE-2024-33268 | CRITICAL | 9.8 | 0.5% | Apr 29, 2024 | SQL Injection vulnerability in Digincube mdgiftproduct before 1.4.1 allows an attacker to run arbitrary SQL commands via... |
| CVE-2024-33266 | CRITICAL | 9.8 | 0.7% | Apr 29, 2024 | SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary ... |
| CVE-2024-31822 | CRITICAL | 9.8 | 1.9% | Apr 29, 2024 | An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker ... |
| CVE-2024-31820 | CRITICAL | 9.8 | 1.9% | Apr 29, 2024 | An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker ... |
| CVE-2024-31705 | CRITICAL | 9.8 | 1.9% | Apr 29, 2024 | An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insuffici... |
| CVE-2024-33449 | CRITICAL | 9.8 | 0.5% | Apr 29, 2024 | An SSRF issue in the PDFMyURL service allows a remote attacker to obtain sensitive information and execute arbitrary cod... |
| CVE-2024-33445 | CRITICAL | 9.8 | 1.3% | Apr 29, 2024 | An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugin... |
| CVE-2024-33444 | CRITICAL | 9.8 | 0.9% | Apr 29, 2024 | SQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to th... |
| CVE-2024-32491 | CRITICAL | 9.8 | 0.7% | Apr 29, 2024 | An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in use... |
| CVE-2024-3375 | CRITICAL | 9.4 | 0.5% | Apr 29, 2024 | Incorrect Permission Assignment for Critical Resource vulnerability in Havelsan Inc. Dialogue allows Accessing Functiona... |
| CVE-2024-33566 | CRITICAL | 10 | 1.1% | Apr 29, 2024 | Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: fro... |
| CVE-2024-33553 | CRITICAL | 9.8 | 0.6% | Apr 29, 2024 | Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5... |
| CVE-2024-3192 | CRITICAL | 9.6 | 1.0% | Apr 29, 2024 | A vulnerability, which was classified as problematic, was found in MailCleaner up to 2023.03.14. Affected is an unknown ... |
| CVE-2024-3191 | CRITICAL | 9.8 | 5.2% | Apr 29, 2024 | A vulnerability, which was classified as critical, has been found in MailCleaner up to 2023.03.14. This issue affects so... |
| CVE-2024-33546 | CRITICAL | 9.6 | 0.5% | Apr 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allo... |
| CVE-2024-33544 | CRITICAL | 9.3 | 0.6% | Apr 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allo... |
| CVE-2024-33559 | CRITICAL | 9.3 | 3.6% | Apr 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allo... |
| CVE-2024-33551 | CRITICAL | 9.8 | 0.6% | Apr 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core... |
| CVE-2024-4300 | CRITICAL | 9.8 | 0.8% | Apr 29, 2024 | E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the data... |
| CVE-2024-1874 | CRITICAL | 9.4 | 32.6% | Apr 29, 2024 | In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array ... |
| CVE-2024-3342 | CRITICAL | 9.9 | 0.6% | Apr 27, 2024 | The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attri... |
| CVE-2024-30804 | CRITICAL | 9.8 | 0.8% | Apr 26, 2024 | An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbi... |
| CVE-2024-28322 | CRITICAL | 9.8 | 0.8% | Apr 26, 2024 | SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now