2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-52370CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Hive Support Hive Support hive-support allows Upload a ...
CVE-2024-52369CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Optimal Access KBucket kbucket allows Upload a Web Shel...
CVE-2024-52384CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in wpmonks Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, ...
CVE-2024-52382CRITICAL9.8Missing Authorization vulnerability in medmatech Matix Popup Builder medma-matix allows Privilege Escalation.This issue ...
CVE-2024-52380CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in softpulseinfotech Picsmize picsmize allows Upload a Web...
CVE-2024-52379CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in faizalbahasan kineticPay for WooCommerce kineticpay-for...
CVE-2024-52377CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in bdthemes Instant Image Generator ai-image allows Upload...
CVE-2024-52376CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in cmsMinds Boat Rental Plugin for WordPress boat-rental-s...
CVE-2024-52375CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Arttia Creative Datasets Manager by Arttia Creative dat...
CVE-2024-52374CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in DoThatTask Do That Task do-that-task allows Upload a We...
CVE-2024-52373CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Team Devexhub Devexhub Gallery devexhub-gallery allows ...
CVE-2024-52372CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in WebTechGlobal Easy CSV Importer BETA easy-csv-importer ...
CVE-2024-50823CRITICAL9.8A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via th...
CVE-2024-4343CRITICAL9.8A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method within `./private_gpt/...
CVE-2024-49362CRITICAL9.6Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote...
CVE-2024-50833CRITICAL9.8A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the user...
CVE-2024-11209CRITICAL9.8A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the fil...
CVE-2024-10571CRITICAL9.8The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, ...
CVE-2024-50306CRITICAL9.1Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traff...
CVE-2024-40404CRITICAL9.8Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endp...
CVE-2024-43091CRITICAL9.8In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could ...
CVE-2024-52306CRITICAL9.8FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data ...
CVE-2024-52300CRITICAL9macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't ...
CVE-2024-52295CRITICAL9.8DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and...
CVE-2024-48510CRITICAL9.8Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code vi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now