2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-42450CRITICAL10The Versa Director uses PostgreSQL (Postgres) to store operational and configuration data. It is also needed for High Av...
CVE-2024-52402CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in gunghoinc Exclusive Content Password Protect exclusive-content-passwo...
CVE-2024-52401CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog DownloadManager hacklog-downloadmanager allows...
CVE-2024-52675CRITICAL9.8SourceCodester Sentiment Based Movie Rating System 1.0 is vulnerable to SQL Injection in /msrps/movies.php.
CVE-2024-11036CRITICAL9.8The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for Wo...
CVE-2024-11069CRITICAL9.1The WordPress GDPR plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on ...
CVE-2024-51051CRITICAL9.8AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account.
CVE-2024-51053CRITICAL9.8An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0 allows attackers to execut...
CVE-2024-50919CRITICAL9.8Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file format...
CVE-2024-47533CRITICAL9.8Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper a...
CVE-2024-44756CRITICAL9.8NUS-M9 ERP Management Software v3.0.0 was discovered to contain a SQL injection vulnerability via the usercode parameter...
CVE-2024-0012CRITICAL9.8An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access t...
CVE-2024-52434CRITICAL9.1Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Inject...
CVE-2024-52433CRITICAL9.8Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free my-geo-posts-free allows Obj...
CVE-2024-52432CRITICAL9.8Deserialization of Untrusted Data vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Obje...
CVE-2024-52431CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pressaholic WordPr...
CVE-2024-52430CRITICAL9.8Deserialization of Untrusted Data vulnerability in bublick Lis Video Gallery lis-video-gallery allows Object Injection.T...
CVE-2024-52428CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-52316CRITICAL9.8Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication...
CVE-2024-42383CRITICAL9.8Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value ...
CVE-2024-47208CRITICAL9.8Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OF...
CVE-2024-11315CRITICAL9.8The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un...
CVE-2024-11314CRITICAL9.8The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un...
CVE-2024-11313CRITICAL9.8The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un...
CVE-2024-11312CRITICAL9.8The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now