2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-48027CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in xaraartech External featured image from bing external-f...
CVE-2024-48026CRITICAL9.8Deserialization of Untrusted Data vulnerability in GMRobbins Disc Golf Manager disc-golf-manager allows Object Injection...
CVE-2024-47649CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in THATplugin Iconize iconize.This issue affects Iconize: ...
CVE-2024-49257CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Denis Azz Anonim Posting azz-anonim-posting allows Uplo...
CVE-2024-49247CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in SK BuddyPress Better Registration better-bp-re...
CVE-2024-48042CRITICAL9.1Deserialization of Untrusted Data vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows ...
CVE-2024-10022CRITICAL9.8A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an u...
CVE-2024-10021CRITICAL9.8A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. Affected by th...
CVE-2024-9061CRITICAL9.8The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary sho...
CVE-2024-45216CRITICAL9.8Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enable...
CVE-2024-10018CRITICAL9.8Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any une...
CVE-2024-9634CRITICAL9.8The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all ...
CVE-2024-9305CRITICAL9.8The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in...
CVE-2024-9105CRITICAL9.8The UltimateAI plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.8.3. This...
CVE-2024-10004CRITICAL9.1Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in so...
CVE-2024-9486CRITICAL9.8A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enable...
CVE-2024-48782CRITICAL9.8File Upload vulnerability in DYCMS Open-Source Version v2.0.9.41 allows a remote attacker to execute arbitrary code via ...
CVE-2024-48781CRITICAL9.8An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary...
CVE-2024-48779CRITICAL9.8An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary co...
CVE-2024-48411CRITICAL9.8itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload...
CVE-2024-49195CRITICAL9.8Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair
CVE-2024-21216CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t...
CVE-2024-21172CRITICAL9Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). ...
CVE-2024-48914CRITICAL9.1Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's as...
CVE-2024-9986CRITICAL9.8A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now