2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-8338HIGH8.8A vulnerability was found in HFO4 shudong-share 2.4.7. It has been declared as critical. Affected by this vulnerability ...
CVE-2024-8334HIGH8.1A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f. It has been rated as p...
CVE-2024-8260HIGH7.3A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability e...
CVE-2024-8252HIGH8.8The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.14.5 ...
CVE-2024-8016HIGH7.2The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,...
CVE-2024-2694HIGH8.8The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via d...
CVE-2024-5784HIGH7.1The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing ...
CVE-2024-8330HIGH8.86SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regula...
CVE-2024-8329HIGH8.86SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers wit...
CVE-2024-8327HIGH8.8Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific p...
CVE-2024-45490HIGH7.5An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
CVE-2024-2881HIGH8.8Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c in WolfSSL wolfssl5.6.6...
CVE-2024-1545HIGH8.8Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on...
CVE-2024-6672HIGH8.8In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged ...
CVE-2024-45302HIGH7.8RestSharp is a Simple REST and HTTP API Client for .NET. The second argument to `RestRequest.AddHeader` (the header valu...
CVE-2024-34019HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy ...
CVE-2024-34017HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy ...
CVE-2024-43804HIGH8.8Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerabi...
CVE-2024-41964HIGH8.1Kirby is a CMS targeting designers and editors. Kirby allows to restrict the permissions of specific user roles. Users o...
CVE-2024-35133HIGH8.2IBM Security Verify Access 10.0.0 through 10.0.8 OIDC Provider could allow a remote authenticated attacker to conduct ph...
CVE-2024-43957HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sk. Abul Hasan Animated ...
CVE-2024-43955HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Droip allows Fil...
CVE-2024-43943HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift ...
CVE-2024-43942HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wpsoul Greenshift ...
CVE-2024-39658HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salon Booking Syst...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now