2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52591CRITICAL9.3Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService...
CVE-2024-52590MEDIUM6.5Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService...
CVE-2024-52579MEDIUM5.4Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check t...
CVE-2024-51470MEDIUM6.5IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, 9.4 CD, IBM MQ Appliance 9.3 LTS, 9.3 CD, 9.4 LTS, and IBM MQ for HPE...
CVE-2024-49363HIGH7.4Misskey is an open source, federated social media platform. In affected versions FileServerService (media proxy) in gith...
CVE-2024-36694HIGH7.2OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.
CVE-2024-12741HIGH8.4A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Succ...
CVE-2024-56057HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell...
CVE-2024-56055HIGH8.8Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLM...
CVE-2024-56054HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell...
CVE-2024-56053HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS w...
CVE-2024-56052HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell...
CVE-2024-56051HIGH8.8Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Code Inj...
CVE-2024-56050HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell...
CVE-2024-56049HIGH8.5Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLM...
CVE-2024-56048HIGH8.8Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constra...
CVE-2024-56047HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS w...
CVE-2024-55953HIGH8.1DataEase is an open source business analytics tool. Authenticated users can read and deserialize arbitrary files through...
CVE-2024-55952HIGH8.8DataEase is an open source business analytics tool. Authenticated users can remotely execute code through the backend JD...
CVE-2024-54383CRITICAL9.8Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Privilege...
CVE-2024-54381HIGH7.1Missing Authorization vulnerability in Dotstore Advance Menu Manager advance-menu-manager.This issue affects Advance Men...
CVE-2024-49202HIGH7.6Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed ...
CVE-2024-49201MEDIUM4.3Keyfactor Remote File Orchestrator (aka remote-file-orchestrator) 2.8 before 2.8.1 allows Information Disclosure: sensit...
CVE-2024-47040HIGH7.8There is a possible UAF due to a logic error in the code. This could lead to local escalation of privilege with no addit...
CVE-2024-47039MEDIUM5.5In isSlotMarkedSuccessful of BootControl.cpp, there is a possible out of bounds read due to a missing bounds check. This...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now