2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25180 | CRITICAL | 9.8 | 1.0% | Feb 29, 2024 | An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf ... |
| CVE-2024-0864 | CRITICAL | 9.8 | 1.4% | Feb 29, 2024 | Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) a... |
| CVE-2024-25292 | CRITICAL | 9.6 | 1.5% | Feb 29, 2024 | Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML ... |
| CVE-2024-25291 | CRITICAL | 9.8 | 1.6% | Feb 29, 2024 | Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin. |
| CVE-2024-1982 | CRITICAL | 9.1 | 0.8% | Feb 29, 2024 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capa... |
| CVE-2024-1981 | CRITICAL | 9.1 | 1.1% | Feb 29, 2024 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' para... |
| CVE-2024-24525 | CRITICAL | 9.8 | 1.1% | Feb 29, 2024 | An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code vi... |
| CVE-2024-27516 | CRITICAL | 9.8 | 1.5% | Feb 29, 2024 | Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute a... |
| CVE-2024-25833 | CRITICAL | 9.8 | 2.8% | Feb 29, 2024 | F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious ac... |
| CVE-2024-25830 | CRITICAL | 9.8 | 24.0% | Feb 29, 2024 | F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An una... |
| CVE-2024-25128 | CRITICAL | 9.1 | 0.9% | Feb 29, 2024 | Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TY... |
| CVE-2024-25065 | CRITICAL | 9.1 | 47.7% | Feb 29, 2024 | Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.1... |
| CVE-2024-23807 | CRITICAL | 9.8 | 1.5% | Feb 29, 2024 | The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the sca... |
| CVE-2024-23328 | CRITICAL | 9.1 | 1.2% | Feb 29, 2024 | Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase data... |
| CVE-2024-23052 | CRITICAL | 9.8 | 4.9% | Feb 29, 2024 | An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the... |
| CVE-2024-1971 | CRITICAL | 9.8 | 0.8% | Feb 29, 2024 | A vulnerability has been found in Surya2Developer Online Shopping System 1.0 and classified as critical. Affected by thi... |
| CVE-2024-1927 | CRITICAL | 9.8 | 0.8% | Feb 29, 2024 | A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by t... |
| CVE-2024-25422 | CRITICAL | 9.8 | 1.0% | Feb 28, 2024 | SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive info... |
| CVE-2024-25867 | CRITICAL | 9.1 | 0.7% | Feb 28, 2024 | A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute... |
| CVE-2024-25350 | CRITICAL | 9.8 | 0.6% | Feb 28, 2024 | SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tpr... |
| CVE-2024-25170 | CRITICAL | 9.1 | 0.9% | Feb 28, 2024 | An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header. |
| CVE-2024-25169 | CRITICAL | 9.8 | 1.1% | Feb 28, 2024 | An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted reque... |
| CVE-2024-25927 | CRITICAL | 9.8 | 0.6% | Feb 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Joel Starnes postM... |
| CVE-2024-25910 | CRITICAL | 9.8 | 0.6% | Feb 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo... |
| CVE-2024-27099 | CRITICAL | 9.8 | 1.4% | Feb 27, 2024 | The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect `AMQP_VALUE` f... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now