2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4520 | HIGH | 7.5 | 0.5% | Jun 4, 2024 | An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 2... |
| CVE-2024-30525 | HIGH | 7.3 | 0.3% | Jun 4, 2024 | Missing Authorization vulnerability in moveaddons Move Addons for Elementor.This issue affects Move Addons for Elementor... |
| CVE-2024-36857 | HIGH | 7.5 | 2.1% | Jun 4, 2024 | Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface. |
| CVE-2024-30484 | HIGH | 8.8 | 0.3% | Jun 4, 2024 | Missing Authorization vulnerability in RT Easy Builder – Advanced addons for Elementor.This issue affects RT Easy Builde... |
| CVE-2024-29152 | HIGH | 7.5 | 0.4% | Jun 4, 2024 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, ... |
| CVE-2024-25095 | HIGH | 7.5 | 0.4% | Jun 4, 2024 | Insertion of Sensitive Information into Log File vulnerability in Code Parrots Easy Forms for Mailchimp.This issue affec... |
| CVE-2024-36550 | HIGH | 8.8 | 0.2% | Jun 4, 2024 | idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=add&nohre... |
| CVE-2024-36549 | HIGH | 8.8 | 0.3% | Jun 4, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=rev&nohre... |
| CVE-2024-36548 | HIGH | 8.8 | 0.2% | Jun 4, 2024 | idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/vpsCompany_deal.php?mudi=del |
| CVE-2024-36547 | HIGH | 8.8 | 0.2% | Jun 4, 2024 | idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mud... |
| CVE-2024-32871 | HIGH | 7.5 | 0.8% | Jun 4, 2024 | Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood t... |
| CVE-2024-28999 | HIGH | 7.5 | 13.9% | Jun 4, 2024 | The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console. |
| CVE-2024-28996 | HIGH | 7.5 | 0.3% | Jun 4, 2024 | The SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. Attack complexity is high for t... |
| CVE-2024-34792 | HIGH | 7.2 | 1.1% | Jun 4, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in dexta Dextaz Ping a... |
| CVE-2024-34554 | HIGH | 8.8 | 0.5% | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm ... |
| CVE-2024-34552 | HIGH | 8.8 | 0.5% | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm ... |
| CVE-2024-34384 | HIGH | 8.8 | 0.6% | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SinaExtra Sina Extension... |
| CVE-2024-33628 | HIGH | 8.8 | 0.6% | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in XforWooCommerce allows P... |
| CVE-2024-36800 | HIGH | 7.5 | 0.7% | Jun 4, 2024 | A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID param... |
| CVE-2024-33557 | HIGH | 8.8 | 0.6% | Jun 4, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allow... |
| CVE-2024-29170 | HIGH | 8.1 | 0.3% | Jun 4, 2024 | Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent ... |
| CVE-2024-4254 | HIGH | 7.1 | 0.5% | Jun 4, 2024 | The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable ... |
| CVE-2024-37065 | HIGH | 7.8 | 0.2% | Jun 4, 2024 | Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously... |
| CVE-2024-37064 | HIGH | 7.8 | 0.2% | Jun 4, 2024 | Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, e... |
| CVE-2024-37063 | HIGH | 7.8 | 0.3% | Jun 4, 2024 | A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library all... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now