2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-52384CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in wpmonks Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, ...
CVE-2024-52382CRITICAL9.8Missing Authorization vulnerability in medmatech Matix Popup Builder medma-matix allows Privilege Escalation.This issue ...
CVE-2024-52380CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in softpulseinfotech Picsmize picsmize allows Upload a Web...
CVE-2024-52379CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in faizalbahasan kineticPay for WooCommerce kineticpay-for...
CVE-2024-52377CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in bdthemes Instant Image Generator ai-image allows Upload...
CVE-2024-52376CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in cmsMinds Boat Rental Plugin for WordPress boat-rental-s...
CVE-2024-52375CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Arttia Creative Datasets Manager by Arttia Creative dat...
CVE-2024-52374CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in DoThatTask Do That Task do-that-task allows Upload a We...
CVE-2024-52373CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Team Devexhub Devexhub Gallery devexhub-gallery allows ...
CVE-2024-52372CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in WebTechGlobal Easy CSV Importer BETA easy-csv-importer ...
CVE-2024-50823CRITICAL9.8A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via th...
CVE-2024-4343CRITICAL9.8A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method within `./private_gpt/...
CVE-2024-49362CRITICAL9.6Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote...
CVE-2024-50833CRITICAL9.8A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the user...
CVE-2024-11209CRITICAL9.8A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the fil...
CVE-2024-10571CRITICAL9.8The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, ...
CVE-2024-50306CRITICAL9.1Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traff...
CVE-2024-40404CRITICAL9.8Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endp...
CVE-2024-43091CRITICAL9.8In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could ...
CVE-2024-52306CRITICAL9.8FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data ...
CVE-2024-52300CRITICAL9macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't ...
CVE-2024-52295CRITICAL9.8DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and...
CVE-2024-48510CRITICAL9.8Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code vi...
CVE-2024-11028CRITICAL9.8The MultiManager WP – Manage All Your WordPress Sites Easily plugin for WordPress is vulnerable to Authentication Bypass...
CVE-2024-8938CRITICAL9.2CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now