2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-48030CRITICAL9.8Deserialization of Untrusted Data vulnerability in Webextends Telecash Ricaricaweb telecash-ricaricaweb allows Object In...
CVE-2024-48028CRITICAL9.8Deserialization of Untrusted Data vulnerability in Boyan Raichev IP Loc8 ip-loc8 allows Object Injection.This issue affe...
CVE-2024-48027CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in xaraartech External featured image from bing external-f...
CVE-2024-48026CRITICAL9.8Deserialization of Untrusted Data vulnerability in GMRobbins Disc Golf Manager disc-golf-manager allows Object Injection...
CVE-2024-47649CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in THATplugin Iconize iconize.This issue affects Iconize: ...
CVE-2024-49257CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in Denis Azz Anonim Posting azz-anonim-posting allows Uplo...
CVE-2024-49247CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in SK BuddyPress Better Registration better-bp-re...
CVE-2024-48042CRITICAL9.1Deserialization of Untrusted Data vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows ...
CVE-2024-10022CRITICAL9.8A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an u...
CVE-2024-10021CRITICAL9.8A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as critical. Affected by th...
CVE-2024-9061CRITICAL9.8The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary sho...
CVE-2024-45216CRITICAL9.8Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enable...
CVE-2024-10018CRITICAL9.8Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any une...
CVE-2024-9634CRITICAL9.8The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all ...
CVE-2024-9305CRITICAL9.8The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in...
CVE-2024-9105CRITICAL9.8The UltimateAI plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.8.3. This...
CVE-2024-10004CRITICAL9.1Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in so...
CVE-2024-9486CRITICAL9.8A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enable...
CVE-2024-48782CRITICAL9.8File Upload vulnerability in DYCMS Open-Source Version v2.0.9.41 allows a remote attacker to execute arbitrary code via ...
CVE-2024-48781CRITICAL9.8An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary...
CVE-2024-48779CRITICAL9.8An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary co...
CVE-2024-48411CRITICAL9.8itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload...
CVE-2024-49195CRITICAL9.8Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair
CVE-2024-21216CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t...
CVE-2024-21172CRITICAL9Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now