2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-4185HIGH8.1The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authenticat...
CVE-2024-2663HIGH8.3The ZD YouTube FLV Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and i...
CVE-2024-1895HIGH7.5The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object I...
CVE-2024-4225HIGH7.6Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), b...
CVE-2024-31837HIGH8.4DMitry (Deepmagic Information Gathering Tool) 1.3a has a format-string vulnerability, with a threat model similar to CVE...
CVE-2024-34050HIGH7.5Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return uint64(b[2])<<...
CVE-2024-34049HIGH7.5Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return plmnIdString[0...
CVE-2024-34046HIGH7.5The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->sctpParam...
CVE-2024-34045HIGH7.5The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->counters[...
CVE-2024-27518HIGH7.8An issue in SUPERAntiSyware Professional X 10.0.1262 and 10.0.1264 allows unprivileged attackers to escalate privileges ...
CVE-2024-33271HIGH7.5An issue in FME Modules eventsmanager before 4.4.0 allows an attacker to obtain sensitive information from the ps_custom...
CVE-2024-31801HIGH7.5Directory Traversal vulnerability in NEXSYS-ONE before v.Rev.15320 allows a remote attacker to obtain sensitive informat...
CVE-2024-0840HIGH8.8The Grandstream UCM Series IP PBX before firmware version 1.0.20.52 is affected by a parameter injection vulnerability i...
CVE-2024-33443HIGH7.1An issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsControll...
CVE-2024-33438HIGH8File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted ...
CVE-2024-33338HIGH7.3Cross Site Scripting vulnerability in jizhicms v.2.5.4 allows a remote attacker to obtain sensitive information via a cr...
CVE-2024-31821HIGH8SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows...
CVE-2024-28320HIGH7.6Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate ...
CVE-2024-32493HIGH8.8An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able ...
CVE-2024-32492HIGH7.1An issue was discovered in Znuny 7.0.1 through 7.0.16 where the ticket detail view in the customer front allows the exec...
CVE-2024-32269HIGH7.5An issue in Yonganda YAD-LOJ V3.0.561 allows a remote attacker to cause a denial of service via a crafted packet.
CVE-2024-31621HIGH7.6An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted sc...
CVE-2024-34010HIGH8.2Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber...
CVE-2024-1969HIGH8.2Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Secomea GateManager (webserver m...
CVE-2024-1579HIGH8.1Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Secomea GateManager (Webserver module...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now