2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-33276CRITICAL9.8SQL Injection vulnerability in FME Modules preorderandnotication v.3.1.0 and before allows a remote attacker to run arbi...
CVE-2024-33269CRITICAL9.8SQL Injection vulnerability in Prestaddons flashsales 1.9.7 and before allows an attacker to run arbitrary SQL commands ...
CVE-2024-33268CRITICAL9.8SQL Injection vulnerability in Digincube mdgiftproduct before 1.4.1 allows an attacker to run arbitrary SQL commands via...
CVE-2024-33266CRITICAL9.8SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary ...
CVE-2024-31822CRITICAL9.8An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker ...
CVE-2024-31820CRITICAL9.8An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker ...
CVE-2024-31705CRITICAL9.8An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insuffici...
CVE-2024-33449CRITICAL9.8An SSRF issue in the PDFMyURL service allows a remote attacker to obtain sensitive information and execute arbitrary cod...
CVE-2024-33445CRITICAL9.8An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugin...
CVE-2024-33444CRITICAL9.8SQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to th...
CVE-2024-32491CRITICAL9.8An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in use...
CVE-2024-3375CRITICAL9.4Incorrect Permission Assignment for Critical Resource vulnerability in Havelsan Inc. Dialogue allows Accessing Functiona...
CVE-2024-33566CRITICAL10Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: fro...
CVE-2024-33553CRITICAL9.8Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5...
CVE-2024-3192CRITICAL9.6A vulnerability, which was classified as problematic, was found in MailCleaner up to 2023.03.14. Affected is an unknown ...
CVE-2024-3191CRITICAL9.8A vulnerability, which was classified as critical, has been found in MailCleaner up to 2023.03.14. This issue affects so...
CVE-2024-33546CRITICAL9.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allo...
CVE-2024-33544CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allo...
CVE-2024-33559CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allo...
CVE-2024-33551CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core...
CVE-2024-4300CRITICAL9.8E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the data...
CVE-2024-1874CRITICAL9.4In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array ...
CVE-2024-3342CRITICAL9.9The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attri...
CVE-2024-30804CRITICAL9.8An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbi...
CVE-2024-28322CRITICAL9.8SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now