2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-25180CRITICAL9.8An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf ...
CVE-2024-0864CRITICAL9.8Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) a...
CVE-2024-25292CRITICAL9.6Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML ...
CVE-2024-25291CRITICAL9.8Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.
CVE-2024-1982CRITICAL9.1The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capa...
CVE-2024-1981CRITICAL9.1The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' para...
CVE-2024-24525CRITICAL9.8An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code vi...
CVE-2024-27516CRITICAL9.8Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute a...
CVE-2024-25833CRITICAL9.8F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious ac...
CVE-2024-25830CRITICAL9.8F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An una...
CVE-2024-25128CRITICAL9.1Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TY...
CVE-2024-25065CRITICAL9.1Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.1...
CVE-2024-23807CRITICAL9.8The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the sca...
CVE-2024-23328CRITICAL9.1Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase data...
CVE-2024-23052CRITICAL9.8An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the...
CVE-2024-1971CRITICAL9.8A vulnerability has been found in Surya2Developer Online Shopping System 1.0 and classified as critical. Affected by thi...
CVE-2024-1927CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by t...
CVE-2024-25422CRITICAL9.8SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive info...
CVE-2024-25867CRITICAL9.1A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute...
CVE-2024-25350CRITICAL9.8SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tpr...
CVE-2024-25170CRITICAL9.1An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.
CVE-2024-25169CRITICAL9.8An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted reque...
CVE-2024-25927CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Joel Starnes postM...
CVE-2024-25910CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo...
CVE-2024-27099CRITICAL9.8The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect `AMQP_VALUE` f...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now