2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-12470 | CRITICAL | 9.8 | 0.6% | Jan 7, 2025 | The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to... |
| CVE-2024-12264 | CRITICAL | 9.8 | 0.7% | Jan 7, 2025 | The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ... |
| CVE-2024-12252 | CRITICAL | 9.8 | 3.1% | Jan 7, 2025 | The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remo... |
| CVE-2024-12402 | CRITICAL | 9.8 | 0.6% | Jan 7, 2025 | The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege e... |
| CVE-2024-53932 | CRITICAL | 9.1 | 0.3% | Jan 6, 2025 | The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.... |
| CVE-2024-53931 | CRITICAL | 9.1 | 0.3% | Jan 6, 2025 | The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any appli... |
| CVE-2024-46981 | CRITICAL | 9.8 | 7.8% | Jan 6, 2025 | Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua... |
| CVE-2024-55074 | CRITICAL | 9 | 0.6% | Jan 6, 2025 | The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a cra... |
| CVE-2024-56828 | CRITICAL | 9.8 | 0.9% | Jan 6, 2025 | File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/memb... |
| CVE-2024-55529 | CRITICAL | 9.8 | 0.6% | Jan 6, 2025 | Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template. |
| CVE-2024-54880 | CRITICAL | 9.1 | 0.9% | Jan 6, 2025 | SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user t... |
| CVE-2024-54879 | CRITICAL | 9.1 | 0.9% | Jan 6, 2025 | SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user t... |
| CVE-2024-46622 | CRITICAL | 9.8 | 0.6% | Jan 6, 2025 | An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.... |
| CVE-2024-5594 | CRITICAL | 9.1 | 0.8% | Jan 6, 2025 | OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to ... |
| CVE-2024-20148 | CRITICAL | 9.8 | 0.3% | Jan 6, 2025 | In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (pro... |
| CVE-2024-13145 | CRITICAL | 9.8 | 0.4% | Jan 6, 2025 | A vulnerability classified as critical was found in zhenfeng13 My-Blog 1.0. Affected by this vulnerability is the functi... |
| CVE-2024-13144 | CRITICAL | 9.8 | 0.4% | Jan 6, 2025 | A vulnerability classified as critical has been found in zhenfeng13 My-Blog 1.0. Affected is the function uploadFileByEd... |
| CVE-2024-13136 | CRITICAL | 9.8 | 0.6% | Jan 5, 2025 | A vulnerability was found in wangl1989 mysiteforme 1.0 and classified as critical. Affected by this issue is the functio... |
| CVE-2024-12583 | CRITICAL | 9.9 | 1.4% | Jan 4, 2025 | The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all ... |
| CVE-2024-55507 | CRITICAL | 9.8 | 0.6% | Jan 3, 2025 | An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e... |
| CVE-2024-55078 | CRITICAL | 9.8 | 0.7% | Jan 3, 2025 | An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0-JAVA v11.3.3 allows attac... |
| CVE-2024-9140 | CRITICAL | 9.8 | 1.8% | Jan 3, 2025 | Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2... |
| CVE-2024-53842 | CRITICAL | 9.8 | 0.3% | Jan 3, 2025 | In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to a missing bounds check... |
| CVE-2024-56249 | CRITICAL | 9.1 | 1.2% | Jan 2, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Ludwig You WPMasterToolKit wpmastertoolkit allows Uploa... |
| CVE-2024-56829 | CRITICAL | 10 | 0.5% | Jan 2, 2025 | Huang Yaoshi Pharmaceutical Management Software through 16.0 allows arbitrary file upload via a .asp filename in the fil... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now