2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52378HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 DigiPass digipass...
CVE-2024-52377CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in bdthemes Instant Image Generator ai-image allows Upload...
CVE-2024-52376CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in cmsMinds Boat Rental Plugin for WordPress boat-rental-s...
CVE-2024-52375CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Arttia Creative Datasets Manager by Arttia Creative dat...
CVE-2024-52374CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in DoThatTask Do That Task do-that-task allows Upload a We...
CVE-2024-52373CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Team Devexhub Devexhub Gallery devexhub-gallery allows ...
CVE-2024-52372CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in WebTechGlobal Easy CSV Importer BETA easy-csv-importer ...
CVE-2024-52371HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DonnellC Global Gateway ...
CVE-2024-50831HIGH7.2A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the usernam...
CVE-2024-50830HIGH7.2A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Proje...
CVE-2024-50829HIGH7.2A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0...
CVE-2024-50828HIGH7.2A SQL Injection vulnerability was found in /admin/edit_department.php in kashipara E-learning Management System Project ...
CVE-2024-50827HIGH7.2A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 ...
CVE-2024-50826HIGH7.2A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 ...
CVE-2024-50825HIGH7.2A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 ...
CVE-2024-50824HIGH7.2A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via th...
CVE-2024-50823CRITICAL9.8A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via th...
CVE-2024-4343CRITICAL9.8A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method within `./private_gpt/...
CVE-2024-4311MEDIUM5.4zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password chan...
CVE-2024-49362CRITICAL9.6Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote...
CVE-2024-48284MEDIUM4.8A Reflected Cross-Site Scripting (XSS) vulnerability was found in the /search-result.php page of the PHPGurukul User Reg...
CVE-2024-3502HIGH8.1In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists where account rec...
CVE-2024-3501HIGH8.1In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclus...
CVE-2024-3379HIGH8.1In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to ...
CVE-2024-1682MEDIUM4.3An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now