2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-27859HIGH8.8The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14....
CVE-2024-13059HIGH7.2A vulnerability in mintplex-labs/anything-llm prior to version 1.3.1 allows for path traversal due to improper handling ...
CVE-2024-57408HIGH7.2An arbitrary file upload vulnerability in the component /comm/upload of cool-admin-java v1.0 allows attackers to execute...
CVE-2024-57407HIGH7.3An arbitrary file upload vulnerability in the component /userPicture of Timo v2.0.3 allows attackers to execute arbitrar...
CVE-2024-54954HIGH8OneBlog v2.3.6 was discovered to contain a template injection vulnerability via the template management department.
CVE-2024-10334HIGH7.3A vulnerability exists in the VideONet product included in the listed System 800xA versions, where VideONet is used.  A...
CVE-2024-11621HIGH8.8Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to...
CVE-2024-8684HIGH8.3OS Command Injection vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability...
CVE-2024-13440HIGH8.2The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all v...
CVE-2024-57606HIGH7.5SQL injection vulnerability in Beijing Guoju Information Technology Co., Ltd JeecgBoot v.3.7.2 allows a remote attacker ...
CVE-2024-57357HIGH8An issue in TPLINK TL-WPA 8630 TL-WPA8630(US)_V2_2.0.4 Build 20230427 allows a remote attacker to execute arbitrary code...
CVE-2024-55272HIGH7.5An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via the chat window function...
CVE-2024-7425HIGH7.2The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege...
CVE-2024-9664HIGH7.2The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4...
CVE-2024-7419HIGH8.8The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, ...
CVE-2024-52884HIGH7.5An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of we...
CVE-2024-52883HIGH7.5An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnera...
CVE-2024-52881HIGH7.5An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded ...
CVE-2024-48091HIGH7.8Tally Prime Edit Log v2.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. Thi...
CVE-2024-13352HIGH7.1The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page...
CVE-2024-57609HIGH8.6An issue in Kanaries Inc Pygwalker before v.0.4.9.9 allows a remote attacker to obtain sensitive information and execute...
CVE-2024-57392HIGH7.5Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can caus...
CVE-2024-56889HIGH7.5Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauth...
CVE-2024-55241HIGH8.8An issue in deep-diver LLM-As-Chatbot before commit 99c2c03 allows a remote attacker to execute arbitrary code via the m...
CVE-2024-54909HIGH8.1A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now