2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54370 | CRITICAL | 9.9 | 0.6% | Dec 16, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member ... |
| CVE-2024-54369 | CRITICAL | 9.1 | 1.5% | Dec 16, 2024 | Missing Authorization vulnerability in ThemeHunk Zita Site Builder ai-site-builder allows Accessing Functionality Not Pr... |
| CVE-2024-54368 | CRITICAL | 9.6 | 0.3% | Dec 16, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in rubengarzajr GitSync git-sync allows Code Injection.This issue affect... |
| CVE-2024-54367 | CRITICAL | 9.8 | 0.7% | Dec 16, 2024 | Deserialization of Untrusted Data vulnerability in Ultimate Member ForumWP forumwp allows Object Injection.This issue af... |
| CVE-2024-54363 | CRITICAL | 9.8 | 1.8% | Dec 16, 2024 | Incorrect Privilege Assignment vulnerability in saiful.total Wp NssUser Register wp-nssuser-register allows Privilege Es... |
| CVE-2024-54361 | CRITICAL | 9.3 | 0.5% | Dec 16, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tenteeglobal Insta... |
| CVE-2024-49775 | CRITICAL | 9.8 | 1.5% | Dec 16, 2024 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence ... |
| CVE-2024-12641 | CRITICAL | 9.6 | 1.4% | Dec 16, 2024 | TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a si... |
| CVE-2024-55969 | CRITICAL | 9.1 | 0.6% | Dec 15, 2024 | DocIO in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 throws XMLException during the resaving of a DOCX do... |
| CVE-2024-11715 | CRITICAL | 9.8 | 0.4% | Dec 14, 2024 | The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to... |
| CVE-2024-55956 | CRITICAL | 9.8 | 93.8% | Dec 13, 2024 | In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can impo... |
| CVE-2024-54139 | CRITICAL | 9.6 | 0.2% | Dec 13, 2024 | Combodo iTop is an open source and web-based IT service management platform. Prior to versions 2.7.11, 3.1.2, and 3.2.0.... |
| CVE-2024-54297 | CRITICAL | 9.8 | 0.7% | Dec 13, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in extremeidea vBSSO-lite vbsso-lite allows Authe... |
| CVE-2024-54296 | CRITICAL | 9.8 | 0.7% | Dec 13, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Codexpert, Inc CoSchool LMS coschool allows Au... |
| CVE-2024-54295 | CRITICAL | 9.8 | 0.7% | Dec 13, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder ListApp Mobile Manager listapp-mob... |
| CVE-2024-54294 | CRITICAL | 9.8 | 0.7% | Dec 13, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Appgenix Infotech Firebase OTP Authentication ... |
| CVE-2024-54293 | CRITICAL | 9.8 | 0.6% | Dec 13, 2024 | Incorrect Privilege Assignment vulnerability in CE21 CE21 Suite ce21-suite allows Privilege Escalation.This issue affect... |
| CVE-2024-54292 | CRITICAL | 9.3 | 0.8% | Dec 13, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsplate Appsplat... |
| CVE-2024-54273 | CRITICAL | 9.8 | 0.7% | Dec 13, 2024 | Deserialization of Untrusted Data vulnerability in PickPlugins Mail Picker mail-picker allows Object Injection.This issu... |
| CVE-2024-54262 | CRITICAL | 9.9 | 1.4% | Dec 13, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in sidngr Import Export For WooCommerce import-export-for-... |
| CVE-2024-54261 | CRITICAL | 10 | 0.6% | Dec 13, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK Digital Agency ... |
| CVE-2024-54239 | CRITICAL | 9.8 | 0.9% | Dec 13, 2024 | Missing Authorization vulnerability in dugudlabs Eyewear prescription form eyewear-prescription-form allows Privilege Es... |
| CVE-2024-54234 | CRITICAL | 9.3 | 0.5% | Dec 13, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wp-buy Limit Login... |
| CVE-2024-28980 | CRITICAL | 9.8 | 0.5% | Dec 13, 2024 | Dell RecoverPoint for VMs, version(s) 6.0.x contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability ... |
| CVE-2024-48007 | CRITICAL | 9.8 | 0.4% | Dec 13, 2024 | Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability. A Remote unauthentica... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now