2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-49227CRITICAL9.8Deserialization of Untrusted Data vulnerability in foter Free Stock Photos Foter free-stock-photos-foter allows Object I...
CVE-2024-49226HIGH8.8Deserialization of Untrusted Data vulnerability in taketin TAKETIN To WP Membership taketin-to-wp-membership allows Obje...
CVE-2024-49218CRITICAL9.8Deserialization of Untrusted Data vulnerability in Al Imran Akash Recently recently-viewed-most-viewed-and-sold-products...
CVE-2024-49216CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in jclay06 Feed Comments Number feed-comments-number allow...
CVE-2024-48035CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in takayukii ACF Images Search And Insert acf-images-searc...
CVE-2024-48034CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in fliperrr Creates 3D Flipbook, PDF Flipbook create-flipb...
CVE-2024-48030CRITICAL9.8Deserialization of Untrusted Data vulnerability in Webextends Telecash Ricaricaweb telecash-ricaricaweb allows Object In...
CVE-2024-48029HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-48028CRITICAL9.8Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 ip-loc8 allows Object Injection.This issue affe...
CVE-2024-48027CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in xaraartech External featured image from bing external-f...
CVE-2024-48026CRITICAL9.8Deserialization of Untrusted Data vulnerability in GMRobbins Disc Golf Manager disc-golf-manager allows Object Injection...
CVE-2024-47649CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in THATplugin Iconize iconize.This issue affects Iconize: ...
CVE-2024-47645HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Danish Ali Malik Top Bar...
CVE-2024-47637HIGH8.8Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.Th...
CVE-2024-47351HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxS...
CVE-2024-22034MEDIUM5.5Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker t...
CVE-2024-22033MEDIUM6.3The OBS service obs-service-download_url was vulnerable to a command injection vulnerability. The attacker could provide...
CVE-2024-22032HIGH7.1A vulnerability has been identified in which an RKE1 cluster keeps constantly reconciling when secrets encryption confi...
CVE-2024-22030HIGH8A vulnerability has been identified within Rancher that can be exploited in narrow circumstances through a man-in-the-m...
CVE-2024-22029HIGH7.8Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalat...
CVE-2024-49271HIGH7.2Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Ad...
CVE-2024-49257CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Denis Azz Anonim Posting azz-anonim-posting allows Uplo...
CVE-2024-49247CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in SK BuddyPress Better Registration better-bp-re...
CVE-2024-48042CRITICAL9.1Deserialization of Untrusted Data vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows ...
CVE-2024-10024HIGH8.8A vulnerability, which was classified as critical, has been found in code-projects Pharmacy Management System 1.0. This ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now