2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-4520HIGH7.5An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 2...
CVE-2024-30525HIGH7.3Missing Authorization vulnerability in moveaddons Move Addons for Elementor.This issue affects Move Addons for Elementor...
CVE-2024-36857HIGH7.5Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.
CVE-2024-30484HIGH8.8Missing Authorization vulnerability in RT Easy Builder – Advanced addons for Elementor.This issue affects RT Easy Builde...
CVE-2024-29152HIGH7.5An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, ...
CVE-2024-25095HIGH7.5Insertion of Sensitive Information into Log File vulnerability in Code Parrots Easy Forms for Mailchimp.This issue affec...
CVE-2024-36550HIGH8.8idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=add&nohre...
CVE-2024-36549HIGH8.8idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=rev&nohre...
CVE-2024-36548HIGH8.8idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/vpsCompany_deal.php?mudi=del
CVE-2024-36547HIGH8.8idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mud...
CVE-2024-32871HIGH7.5Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood t...
CVE-2024-28999HIGH7.5The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.
CVE-2024-28996HIGH7.5The SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. Attack complexity is high for t...
CVE-2024-34792HIGH7.2Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in dexta Dextaz Ping a...
CVE-2024-34554HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm ...
CVE-2024-34552HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm ...
CVE-2024-34384HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SinaExtra Sina Extension...
CVE-2024-33628HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in XforWooCommerce allows P...
CVE-2024-36800HIGH7.5A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID param...
CVE-2024-33557HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allow...
CVE-2024-29170HIGH8.1Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent ...
CVE-2024-4254HIGH7.1The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable ...
CVE-2024-37065HIGH7.8Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously...
CVE-2024-37064HIGH7.8Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, e...
CVE-2024-37063HIGH7.8A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library all...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now