2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-50484CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Lindeni Mahlalela Multi Purpose Mail Form multi-purpose...
CVE-2024-50482CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Chetan Khandla Woocommerce Product Design woo-product-d...
CVE-2024-50480CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in azexo Marketing Automation by AZEXO marketing-automatio...
CVE-2024-45656CRITICAL9.8IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030.00 through FW1030.61, ...
CVE-2024-44217CRITICAL9.1A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in iOS 1...
CVE-2024-50496CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For WordPress ar-for-wordpress allows Up...
CVE-2024-50495CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in nunomorgadinho Plugin Propagator wp-propagator allows U...
CVE-2024-48356CRITICAL9.8LyLme Spage <=1.6.0 is vulnerable to SQL Injection via /admin/group.php.
CVE-2024-40867CRITICAL9.6A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPa...
CVE-2024-48465CRITICAL9.8The MRBS version 1.5.0 has an SQL injection vulnerability in the edit_entry_handler.php file, specifically in the rooms%...
CVE-2024-48357CRITICAL9.8LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php.
CVE-2024-39205CRITICAL9.8An issue in pyload-ng v0.5.0b3.dev85 running under python3.11 or below allows attackers to execute arbitrary code via a ...
CVE-2024-10450CRITICAL9.8A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as cri...
CVE-2024-10449CRITICAL9.8A vulnerability, which was classified as critical, was found in Codezips Hospital Appointment System 1.0. This affects a...
CVE-2024-50497CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-50491CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MicahBlu RSVP ME r...
CVE-2024-50483CRITICAL9.8Authorization Bypass Through User-Controlled Key vulnerability in Tareq Hasan Meetup meetup allows Privilege Escalation....
CVE-2024-50479CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chenyenming Woocom...
CVE-2024-50478CRITICAL9.8Authentication Bypass by Primary Weakness vulnerability in Swoop 1-Click Login: Passwordless Authentication allows Authe...
CVE-2024-50498CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console ...
CVE-2024-50492CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Cod...
CVE-2024-50489CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-wo...
CVE-2024-50487CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo MaanStore API maanstore-api allows Authe...
CVE-2024-50486CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Acnoo Acnoo Flutter API acnoo-flutter-api allo...
CVE-2024-50477CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Stacks Stacks Mobile App Builder stacks-mobile...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now