2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-40765CRITICAL9.8An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions ...
CVE-2024-53704CRITICAL9.8An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authe...
CVE-2024-40762CRITICAL9.8Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in the SonicOS SSLVPN authentication token generator...
CVE-2024-13195CRITICAL9.8A vulnerability was found in donglight bookstore电商书城系统说明 1.0.0. It has been classified as critical. This affects the fun...
CVE-2024-13191CRITICAL9.8A vulnerability, which was classified as critical, has been found in ZeroWdd myblog 1.0. This issue affects the function...
CVE-2024-13189CRITICAL9.8A vulnerability classified as critical has been found in ZeroWdd myblog 1.0. This affects an unknown part of the file sr...
CVE-2024-54676CRITICAL9.8Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Def...
CVE-2024-11350CRITICAL9.8The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i...
CVE-2024-11635CRITICAL9.8The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi...
CVE-2024-11613CRITICAL9.8The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary File Read, and Arbitrar...
CVE-2024-50603CRITICAL9.8An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutraliza...
CVE-2024-54819CRITICAL9.1I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input valid...
CVE-2024-35532CRITICAL9.1An XML External Entity (XXE) injection vulnerability in Intersec Geosafe-ea 2022.12, 2022.13, and 2022.14 allows attacke...
CVE-2024-55414CRITICAL9.8A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged u...
CVE-2024-50660CRITICAL9.8File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the file upload f...
CVE-2024-50658CRITICAL9.8Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code vi...
CVE-2024-55556CRITICAL9.8A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote com...
CVE-2024-56290CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silverplugins217 M...
CVE-2024-56284CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sslplugins SSL Wir...
CVE-2024-56278CRITICAL9.1Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders Inc., WP Ultimate Exporter wp-ult...
CVE-2024-56273CRITICAL9.8Missing Authorization vulnerability in wpvividplugins WPvivid Backup and Migration wpvivid-backuprestore allows Accessin...
CVE-2024-49649CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-49222CRITICAL9.8Deserialization of Untrusted Data vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Object Injecti...
CVE-2024-43243CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in themeglow JobBoard Job listing job-board-light allows U...
CVE-2024-8855CRITICAL9.8The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now