2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-40552HIGH8.8PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray param...
CVE-2024-40551HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows at...
CVE-2024-40550HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302....
CVE-2024-40549HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows a...
CVE-2024-40548HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attack...
CVE-2024-40546HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attacke...
CVE-2024-40545HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows att...
CVE-2024-40544HIGH8.8PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#mainten...
CVE-2024-40543HIGH8.8PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?...
CVE-2024-40522HIGH8.8There is a remote code execution vulnerability in SeaCMS 12.9. The vulnerability is caused by phomebak.php writing some ...
CVE-2024-40521HIGH8.8SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is due to the fact that although admin_template...
CVE-2024-40520HIGH8.8SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_config_mark.php directly spl...
CVE-2024-40519HIGH8.8SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_smtp.php directly splicing a...
CVE-2024-40518HIGH8.8SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing...
CVE-2024-38735HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-38717HIGH7.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Booking Ultra Pro allows...
CVE-2024-39903HIGH7.5Solara is a pure Python, React-style framework for scaling Jupyter and web apps. A Local File Inclusion (LFI) vulnerabil...
CVE-2024-38706HIGH8.8Path Traversal: '.../...//' vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue affects HT Mega: from n/a...
CVE-2024-37940HIGH7.4Cross-Site Request Forgery (CSRF) vulnerability in Seraphinite Solutions Seraphinite Accelerator (Full, premium).This is...
CVE-2024-37932HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in anhvnit Woocommerce Open...
CVE-2024-37928HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NooTheme Jobmonster allo...
CVE-2024-37564HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PayPlus LTD PayPlu...
CVE-2024-37560HIGH8Improper Privilege Management vulnerability in IqbalRony WP User Switch allows Privilege Escalation.This issue affects W...
CVE-2024-37213HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in guru-aliexpress AliNext ali2woo-lite allows Cross Site Request Forger...
CVE-2024-35773HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in WPJohnny, zerOneIT Comment Reply Email allows Cross-Site Scripting (X...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now