2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-28850HIGH8.1WP Crontrol controls the cron events on WordPress websites. WP Crontrol includes a feature that allows administrative u...
CVE-2024-28107HIGH8.8phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection ...
CVE-2024-28105HIGH7.2phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The category imag...
CVE-2024-27299HIGH8.8phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection v...
CVE-2024-30205HIGH7.1In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
CVE-2024-30202HIGH7.8In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6....
CVE-2024-28434HIGH7.6The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg fil...
CVE-2024-28387HIGH7.5An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt compone...
CVE-2024-25002HIGH8.8Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access t...
CVE-2024-25964HIGH7.5Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A remote unauthenticated at...
CVE-2024-24899HIGH7.2Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler ao...
CVE-2024-24897HIGH8.1Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in openEuler A-Tune-Co...
CVE-2024-24892HIGH8.1Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Privilege Managemen...
CVE-2024-24890HIGH7.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler ga...
CVE-2024-21505HIGH7.5Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format a...
CVE-2024-1962HIGH8.8The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attac...
CVE-2024-29071HIGH8.8HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated at...
CVE-2024-28041HIGH8.8HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary comm...
CVE-2024-29188HIGH7.9WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action ...
CVE-2024-29187HIGH7.3WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs...
CVE-2024-29194HIGH8.3OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation o...
CVE-2024-30156HIGH7.5Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, all...
CVE-2024-24725HIGH8.8Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POS...
CVE-2024-23755HIGH8.8ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is in...
CVE-2024-1603HIGH7.5paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now