2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-35286CRITICAL9.8A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to cond...
CVE-2024-35285CRITICAL9.8A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to cond...
CVE-2024-48659CRITICAL9.8An issue in DCME-320-L <=9.3.2.114 allows a remote attacker to execute arbitrary code via the log_u_umount.php component...
CVE-2024-48509CRITICAL9.8Learning with Texts (LWT) 2.0.3 is vulnerable to SQL Injection. This occurs when the application fails to properly sanit...
CVE-2024-47223CRITICAL9.4A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.20...
CVE-2024-49368CRITICAL9.8Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logr...
CVE-2024-47685CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr...
CVE-2024-43689CRITICAL9.8Stack-based buffer overflow vulnerability exists in ELECOM wireless access points. By processing a specially crafted HTT...
CVE-2024-10196CRITICAL9.8A vulnerability was found in code-projects Pharmacy Management System 1.0 and classified as critical. This issue affects...
CVE-2024-44000CRITICAL9.8Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Auth...
CVE-2024-47634CRITICAL9.8Cross-Site Request Forgery (CSRF) vulnerability in Streamline CartBounty – Save and recover abandoned carts for WooComme...
CVE-2024-49625CRITICAL9.8Deserialization of Untrusted Data vulnerability in sphoid SiteBuilder Dynamic Components sitebuilder-dynamic-components ...
CVE-2024-49624CRITICAL9.8Deserialization of Untrusted Data vulnerability in smartdevth Advanced Advertising System advanced-advertising-system al...
CVE-2024-49610CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in photokiteditor photokit photokit allows Upload a Web Sh...
CVE-2024-49607CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in redhopit WP Dropbox Dropins wp-dropbox-dropins allows U...
CVE-2024-49332CRITICAL9.8Deserialization of Untrusted Data vulnerability in giveawayboost Giveaway Boost giveaway-boost allows Object Injection.T...
CVE-2024-49330CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in brx8r Nice Backgrounds nicebackgrounds allows Upload a ...
CVE-2024-49329CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in vivek2tamrakar WP REST API FNS rest-api-fns allows Uplo...
CVE-2024-49327CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in bepitulaz Woostagram Connect woostagram-connect allows ...
CVE-2024-49326CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Vasileios Kerasiotis Affiliator affiliator-lite allows ...
CVE-2024-49324CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in sovratecdev Sovratec Case Management sovratec-case-mana...
CVE-2024-10195CRITICAL9.8A vulnerability was found in Tecno 4G Portable WiFi TR118 V008-20220830. It has been declared as critical. Affected by t...
CVE-2024-49626CRITICAL9.8Deserialization of Untrusted Data vulnerability in Piyush Patel Shipyaari Shipping Management shipyaari-shipping-managme...
CVE-2024-49611CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in paxmanpwnz Product Website Showcase product-websites-sh...
CVE-2024-49604CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registrati...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now