2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-40522HIGH8.8There is a remote code execution vulnerability in SeaCMS 12.9. The vulnerability is caused by phomebak.php writing some ...
CVE-2024-40521HIGH8.8SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is due to the fact that although admin_template...
CVE-2024-40520HIGH8.8SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_config_mark.php directly spl...
CVE-2024-40519HIGH8.8SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_smtp.php directly splicing a...
CVE-2024-40518HIGH8.8SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by admin_weixin.php directly splicing...
CVE-2024-39917CRITICAL9.8xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an i...
CVE-2024-38736CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Realtyna Realtyna Organic IDX plugin allows Code Inject...
CVE-2024-38735HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-38734CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft...
CVE-2024-38717HIGH7.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Booking Ultra Pro allows...
CVE-2024-38716MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Blue Plugins Events Cale...
CVE-2024-37405MEDIUM6.5Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) a...
CVE-2024-39916MEDIUM6.4FOG is a free open-source cloning/imaging/rescue suite/inventory management system. There is a security issue with the N...
CVE-2024-39914CRITICAL9.8FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker....
CVE-2024-39909MEDIUM6.5KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container...
CVE-2024-39903HIGH7.5Solara is a pure Python, React-style framework for scaling Jupyter and web apps. A Local File Inclusion (LFI) vulnerabil...
CVE-2024-38715MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ExS ExS Widgets allows P...
CVE-2024-38709MEDIUM5.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Milan Petrovic GD Rating...
CVE-2024-38706HIGH8.8Path Traversal: '.../...//' vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue affects HT Mega: from n/a...
CVE-2024-38704MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DynamicWebLab WordPress ...
CVE-2024-38700MEDIUM6.5Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in real...
CVE-2024-37941MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Internal Link Juicer Internal Link Juicer: SEO Auto Linker for WordPr...
CVE-2024-37940HIGH7.4Cross-Site Request Forgery (CSRF) vulnerability in Seraphinite Solutions Seraphinite Accelerator (Full, premium).This is...
CVE-2024-37939MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in VolThemes Patricia Lite.This issue affects Patricia Lite: from n/a th...
CVE-2024-37938MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in MyThemeShop SociallyViral.This issue affects SociallyViral: from n/a ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now