2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-5715HIGH7.1The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape a parameter before outputting it back in the ...
CVE-2024-5472HIGH7.1The WP QuickLaTeX WordPress plugin before 3.8.7 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-5287HIGH7.1The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, wh...
CVE-2024-5167HIGH8.1The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or ...
CVE-2024-5151HIGH7.1The SULly WordPress plugin before 4.3.1 does not sanitise and escape some of its settings, which could allow high privil...
CVE-2024-5080HIGH8.8The wp-eMember WordPress plugin before 10.6.6 does not validate files to be uploaded, which could allow admins to upload...
CVE-2024-5076HIGH8.8The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to m...
CVE-2024-5034HIGH8.8The SULly WordPress plugin before 4.3.1 does not have CSRF checks in some places, which could allow attackers to make lo...
CVE-2024-30213HIGH8.8StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injecti...
CVE-2024-40552HIGH8.8PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray param...
CVE-2024-40551HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows at...
CVE-2024-40550HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302....
CVE-2024-40549HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows a...
CVE-2024-40548HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attack...
CVE-2024-40546HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attacke...
CVE-2024-40545HIGH8.8An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows att...
CVE-2024-40544HIGH8.8PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#mainten...
CVE-2024-40543HIGH8.8PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?...
CVE-2024-40522HIGH8.8There is a remote code execution vulnerability in SeaCMS 12.9. The vulnerability is caused by phomebak.php writing some ...
CVE-2024-40521HIGH8.8SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is due to the fact that although admin_template...
CVE-2024-40520HIGH8.8SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_config_mark.php directly spl...
CVE-2024-40519HIGH8.8SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_smtp.php directly splicing a...
CVE-2024-40518HIGH8.8SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing...
CVE-2024-38735HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-38717HIGH7.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Booking Ultra Pro allows...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now