2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-12470CRITICAL9.8The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to...
CVE-2024-12264CRITICAL9.8The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ...
CVE-2024-12252CRITICAL9.8The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remo...
CVE-2024-12402CRITICAL9.8The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege e...
CVE-2024-53932CRITICAL9.1The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1....
CVE-2024-53931CRITICAL9.1The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any appli...
CVE-2024-46981CRITICAL9.8Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua...
CVE-2024-55074CRITICAL9The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a cra...
CVE-2024-56828CRITICAL9.8File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/memb...
CVE-2024-55529CRITICAL9.8Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template.
CVE-2024-54880CRITICAL9.1SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user t...
CVE-2024-54879CRITICAL9.1SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user t...
CVE-2024-46622CRITICAL9.8An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7....
CVE-2024-5594CRITICAL9.1OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to ...
CVE-2024-20148CRITICAL9.8In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (pro...
CVE-2024-13145CRITICAL9.8A vulnerability classified as critical was found in zhenfeng13 My-Blog 1.0. Affected by this vulnerability is the functi...
CVE-2024-13144CRITICAL9.8A vulnerability classified as critical has been found in zhenfeng13 My-Blog 1.0. Affected is the function uploadFileByEd...
CVE-2024-13136CRITICAL9.8A vulnerability was found in wangl1989 mysiteforme 1.0 and classified as critical. Affected by this issue is the functio...
CVE-2024-12583CRITICAL9.9The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all ...
CVE-2024-55507CRITICAL9.8An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e...
CVE-2024-55078CRITICAL9.8An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0-JAVA v11.3.3 allows attac...
CVE-2024-9140CRITICAL9.8Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2...
CVE-2024-53842CRITICAL9.8In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a missing bounds check...
CVE-2024-56249CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Uploa...
CVE-2024-56829CRITICAL10Huang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary file upload via a .asp filename in the fil...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now