2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-13440HIGH8.2The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in all v...
CVE-2024-57606HIGH7.5SQL injection vulnerability in Beijing Guoju Information Technology Co., Ltd JeecgBoot v.3.7.2 allows a remote attacker ...
CVE-2024-57357HIGH8An issue in TPLINK TL-WPA 8630 TL-WPA8630(US)_V2_2.0.4 Build 20230427 allows a remote attacker to execute arbitrary code...
CVE-2024-55272HIGH7.5An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via the chat window function...
CVE-2024-7425HIGH7.2The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege...
CVE-2024-9664HIGH7.2The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4...
CVE-2024-7419HIGH8.8The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, ...
CVE-2024-52884HIGH7.5An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of we...
CVE-2024-52883HIGH7.5An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnera...
CVE-2024-52881HIGH7.5An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded ...
CVE-2024-48091HIGH7.8Tally Prime Edit Log v2.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. Thi...
CVE-2024-13352HIGH7.1The Legull WordPress plugin through 1.2.2 does not sanitise and escape a parameter before outputting it back in the page...
CVE-2024-57609HIGH8.6An issue in Kanaries Inc Pygwalker before v.0.4.9.9 allows a remote attacker to obtain sensitive information and execute...
CVE-2024-57392HIGH7.5Buffer Overflow vulnerability in Proftpd commit 4017eff8 allows a remote attacker to execute arbitrary code and can caus...
CVE-2024-56889HIGH7.5Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauth...
CVE-2024-55241HIGH8.8An issue in deep-diver LLM-As-Chatbot before commit 99c2c03 allows a remote attacker to execute arbitrary code via the m...
CVE-2024-54909HIGH8.1A vulnerability has been identified in GoldPanKit eva-server v4.1.0. It affects the path parameter of the /api/resource/...
CVE-2024-54171HIGH7.1IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticat...
CVE-2024-57426HIGH7.3NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a mali...
CVE-2024-47258HIGH8.12N Access Commander version 2.1 and prior is vulnerable in default settings to Man In The Middle attack due to not verif...
CVE-2024-57668HIGH8.8In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability.
CVE-2024-57610HIGH7.5A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user acco...
CVE-2024-36558HIGH7.5Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h suffers from Cleartext Transmission of ...
CVE-2024-36553HIGH8.1Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h is vulnerable to MITM attack.
CVE-2024-39272HIGH8.2A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML Enterprise Server 3.22....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now