2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32836 | CRITICAL | 9.1 | 0.8% | Apr 24, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay.This ... |
| CVE-2024-32709 | CRITICAL | 9.3 | 5.9% | Apr 24, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-... |
| CVE-2024-32948 | CRITICAL | 9.1 | 0.6% | Apr 24, 2024 | Missing Authorization vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.28. |
| CVE-2024-28613 | CRITICAL | 9.8 | 0.6% | Apr 24, 2024 | SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obta... |
| CVE-2024-32662 | CRITICAL | 9.8 | 0.8% | Apr 23, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulner... |
| CVE-2024-32659 | CRITICAL | 9.8 | 1.2% | Apr 23, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulner... |
| CVE-2024-32658 | CRITICAL | 9.8 | 1.4% | Apr 23, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulner... |
| CVE-2024-33215 | CRITICAL | 9.8 | 0.7% | Apr 23, 2024 | Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterfac... |
| CVE-2024-21511 | CRITICAL | 9.8 | 1.0% | Apr 23, 2024 | Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of t... |
| CVE-2024-32460 | CRITICAL | 9.8 | 1.9% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based based clients using `/bpp:32` legacy `GDI... |
| CVE-2024-32459 | CRITICAL | 9.8 | 3.8% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of... |
| CVE-2024-32458 | CRITICAL | 9.8 | 2.0% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP pri... |
| CVE-2024-32041 | CRITICAL | 9.8 | 1.9% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP pri... |
| CVE-2024-32040 | CRITICAL | 9.8 | 1.9% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP pri... |
| CVE-2024-32039 | CRITICAL | 9.8 | 2.3% | Apr 22, 2024 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients using a version of FreeRDP prior ... |
| CVE-2024-27574 | CRITICAL | 9.1 | 0.6% | Apr 22, 2024 | SQL Injection vulnerability in Trainme Academy version Ichin v.1.3.2 allows a remote attacker to obtain sensitive inform... |
| CVE-2024-4040 | CRITICAL | 10 | 99.5% | Apr 22, 2024 | A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms all... |
| CVE-2024-32238 | CRITICAL | 9.8 | 53.2% | Apr 22, 2024 | H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accesse... |
| CVE-2024-31545 | CRITICAL | 9.4 | 0.6% | Apr 22, 2024 | Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/?page=user/ma... |
| CVE-2024-31666 | CRITICAL | 9.8 | 1.7% | Apr 22, 2024 | An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon... |
| CVE-2024-27349 | CRITICAL | 9.1 | 1.0% | Apr 22, 2024 | Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: f... |
| CVE-2024-27348 | CRITICAL | 9.8 | 99.2% | Apr 22, 2024 | RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1... |
| CVE-2024-29661 | CRITICAL | 9.8 | 0.7% | Apr 22, 2024 | A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload. |
| CVE-2024-32418 | CRITICAL | 9.8 | 1.1% | Apr 22, 2024 | An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component. |
| CVE-2024-31547 | CRITICAL | 9.1 | 0.6% | Apr 19, 2024 | Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/item/view_ite... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now