2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-40552 | HIGH | 8.8 | 0.7% | Jul 12, 2024 | PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray param... |
| CVE-2024-40551 | HIGH | 8.8 | 0.4% | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows at... |
| CVE-2024-40550 | HIGH | 8.8 | 1.0% | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.... |
| CVE-2024-40549 | HIGH | 8.8 | 0.7% | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows a... |
| CVE-2024-40548 | HIGH | 8.8 | 0.7% | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attack... |
| CVE-2024-40546 | HIGH | 8.8 | 0.7% | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attacke... |
| CVE-2024-40545 | HIGH | 8.8 | 0.7% | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows att... |
| CVE-2024-40544 | HIGH | 8.8 | 0.5% | Jul 12, 2024 | PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#mainten... |
| CVE-2024-40543 | HIGH | 8.8 | 0.3% | Jul 12, 2024 | PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?... |
| CVE-2024-40522 | HIGH | 8.8 | 1.2% | Jul 12, 2024 | There is a remote code execution vulnerability in SeaCMS 12.9. The vulnerability is caused by phomebak.php writing some ... |
| CVE-2024-40521 | HIGH | 8.8 | 1.3% | Jul 12, 2024 | SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is due to the fact that although admin_template... |
| CVE-2024-40520 | HIGH | 8.8 | 1.1% | Jul 12, 2024 | SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_config_mark.php directly spl... |
| CVE-2024-40519 | HIGH | 8.8 | 1.1% | Jul 12, 2024 | SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_smtp.php directly splicing a... |
| CVE-2024-40518 | HIGH | 8.8 | 1.2% | Jul 12, 2024 | SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing... |
| CVE-2024-38735 | HIGH | 7.5 | 0.5% | Jul 12, 2024 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2024-38717 | HIGH | 7.1 | 0.4% | Jul 12, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Booking Ultra Pro allows... |
| CVE-2024-39903 | HIGH | 7.5 | 2.9% | Jul 12, 2024 | Solara is a pure Python, React-style framework for scaling Jupyter and web apps. A Local File Inclusion (LFI) vulnerabil... |
| CVE-2024-38706 | HIGH | 8.8 | 0.7% | Jul 12, 2024 | Path Traversal: '.../...//' vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue affects HT Mega: from n/a... |
| CVE-2024-37940 | HIGH | 7.4 | 0.2% | Jul 12, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Seraphinite Solutions Seraphinite Accelerator (Full, premium).This is... |
| CVE-2024-37932 | HIGH | 8.6 | 0.6% | Jul 12, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in anhvnit Woocommerce Open... |
| CVE-2024-37928 | HIGH | 8.6 | 0.6% | Jul 12, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NooTheme Jobmonster allo... |
| CVE-2024-37564 | HIGH | 8.5 | 0.4% | Jul 12, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PayPlus LTD PayPlu... |
| CVE-2024-37560 | HIGH | 8 | 0.4% | Jul 12, 2024 | Improper Privilege Management vulnerability in IqbalRony WP User Switch allows Privilege Escalation.This issue affects W... |
| CVE-2024-37213 | HIGH | 7.1 | 0.2% | Jul 12, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in guru-aliexpress AliNext ali2woo-lite allows Cross Site Request Forger... |
| CVE-2024-35773 | HIGH | 7.1 | 0.2% | Jul 12, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in WPJohnny, zerOneIT Comment Reply Email allows Cross-Site Scripting (X... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now