2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-52384 | CRITICAL | 9.9 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in wpmonks Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, ... |
| CVE-2024-52382 | CRITICAL | 9.8 | 1.0% | Nov 14, 2024 | Missing Authorization vulnerability in medmatech Matix Popup Builder medma-matix allows Privilege Escalation.This issue ... |
| CVE-2024-52380 | CRITICAL | 10 | 1.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in softpulseinfotech Picsmize picsmize allows Upload a Web... |
| CVE-2024-52379 | CRITICAL | 10 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in faizalbahasan kineticPay for WooCommerce kineticpay-for... |
| CVE-2024-52377 | CRITICAL | 10 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in bdthemes Instant Image Generator ai-image allows Upload... |
| CVE-2024-52376 | CRITICAL | 10 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in cmsMinds Boat Rental Plugin for WordPress boat-rental-s... |
| CVE-2024-52375 | CRITICAL | 10 | 1.4% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Arttia Creative Datasets Manager by Arttia Creative dat... |
| CVE-2024-52374 | CRITICAL | 10 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in DoThatTask Do That Task do-that-task allows Upload a We... |
| CVE-2024-52373 | CRITICAL | 10 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Team Devexhub Devexhub Gallery devexhub-gallery allows ... |
| CVE-2024-52372 | CRITICAL | 10 | 0.5% | Nov 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in WebTechGlobal Easy CSV Importer BETA easy-csv-importer ... |
| CVE-2024-50823 | CRITICAL | 9.8 | 0.5% | Nov 14, 2024 | A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via th... |
| CVE-2024-4343 | CRITICAL | 9.8 | 2.6% | Nov 14, 2024 | A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method within `./private_gpt/... |
| CVE-2024-49362 | CRITICAL | 9.6 | 1.0% | Nov 14, 2024 | Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote... |
| CVE-2024-50833 | CRITICAL | 9.8 | 0.6% | Nov 14, 2024 | A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the user... |
| CVE-2024-11209 | CRITICAL | 9.8 | 0.6% | Nov 14, 2024 | A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the fil... |
| CVE-2024-10571 | CRITICAL | 9.8 | 4.8% | Nov 14, 2024 | The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, ... |
| CVE-2024-50306 | CRITICAL | 9.1 | 1.6% | Nov 14, 2024 | Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traff... |
| CVE-2024-40404 | CRITICAL | 9.8 | 0.4% | Nov 13, 2024 | Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endp... |
| CVE-2024-43091 | CRITICAL | 9.8 | 0.5% | Nov 13, 2024 | In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could ... |
| CVE-2024-52306 | CRITICAL | 9.8 | 0.6% | Nov 13, 2024 | FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data ... |
| CVE-2024-52300 | CRITICAL | 9 | 0.4% | Nov 13, 2024 | macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't ... |
| CVE-2024-52295 | CRITICAL | 9.8 | 0.8% | Nov 13, 2024 | DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and... |
| CVE-2024-48510 | CRITICAL | 9.8 | 2.1% | Nov 13, 2024 | Directory Traversal vulnerability in DotNetZip v.1.16.0 and before allows a remote attacker to execute arbitrary code vi... |
| CVE-2024-11028 | CRITICAL | 9.8 | 1.3% | Nov 13, 2024 | The MultiManager WP – Manage All Your WordPress Sites Easily plugin for WordPress is vulnerable to Authentication Bypass... |
| CVE-2024-8938 | CRITICAL | 9.2 | 0.5% | Nov 13, 2024 | CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now