2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35091 | CRITICAL | 9.8 | 0.4% | May 23, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml... |
| CVE-2024-35090 | HIGH | 8.2 | 0.3% | May 23, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysUreportFileMappe... |
| CVE-2024-35086 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in BpmTaskFromMapper.x... |
| CVE-2024-35085 | MEDIUM | 5.4 | 0.2% | May 23, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in ProcessDefinitionMa... |
| CVE-2024-35084 | CRITICAL | 9.8 | 0.4% | May 23, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysMsgPushMapper.xm... |
| CVE-2024-35083 | HIGH | 8.8 | 0.4% | May 23, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysLoginInfoMapper.... |
| CVE-2024-35082 | MEDIUM | 6.3 | 0.3% | May 23, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysOperLogMapper.xm... |
| CVE-2024-35081 | HIGH | 7.5 | 0.5% | May 23, 2024 | LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter in th... |
| CVE-2024-34936 | HIGH | 8.6 | 0.4% | May 23, 2024 | A SQL injection vulnerability in /view/event1.php in Campcodes Complete Web-Based School Management System 1.0 allows an... |
| CVE-2024-34935 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | A SQL injection vulnerability in /view/conversation_history_admin.php in Campcodes Complete Web-Based School Management ... |
| CVE-2024-34934 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | A SQL injection vulnerability in /view/emarks_range_grade_update_form.php in Campcodes Complete Web-Based School Managem... |
| CVE-2024-34933 | MEDIUM | 6.3 | 0.3% | May 23, 2024 | A SQL injection vulnerability in /model/update_grade.php in Campcodes Complete Web-Based School Management System 1.0 al... |
| CVE-2024-34932 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | A SQL injection vulnerability in /model/update_exam.php in Campcodes Complete Web-Based School Management System 1.0 all... |
| CVE-2024-34931 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | A SQL injection vulnerability in /model/update_subject.php in Campcodes Complete Web-Based School Management System 1.0 ... |
| CVE-2024-34930 | MEDIUM | 5.3 | 0.2% | May 23, 2024 | A SQL injection vulnerability in /model/all_events1.php in Campcodes Complete Web-Based School Management System 1.0 all... |
| CVE-2024-34929 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | A SQL injection vulnerability in /view/find_friends.php in Campcodes Complete Web-Based School Management System 1.0 all... |
| CVE-2024-34928 | HIGH | 7.3 | 0.3% | May 23, 2024 | A SQL injection vulnerability in /model/update_subject_routing.php in Campcodes Complete Web-Based School Management Sys... |
| CVE-2024-34927 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | A SQL injection vulnerability in /model/update_classroom.php in Campcodes Complete Web-Based School Management System 1.... |
| CVE-2024-2301 | HIGH | 7.6 | 0.3% | May 23, 2024 | Certain HP LaserJet Pro devices are potentially vulnerable to a Cross-Site Scripting (XSS) attack via the web management... |
| CVE-2024-5085 | CRITICAL | 9.8 | 0.8% | May 23, 2024 | The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up t... |
| CVE-2024-5084 | CRITICAL | 9.8 | 50.9% | May 23, 2024 | The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing fil... |
| CVE-2024-35222 | MEDIUM | 5.9 | 0.3% | May 23, 2024 | Tauri is a framework for building binaries for all major desktop platforms. Remote origin iFrames in Tauri applications ... |
| CVE-2024-5168 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerabi... |
| CVE-2024-4471 | HIGH | 8 | 0.6% | May 23, 2024 | The 140+ Widgets | Best Addons For Elementor – FREE for WordPress is vulnerable to PHP Object Injection in versions up t... |
| CVE-2024-35224 | MEDIUM | 5.4 | 0.3% | May 23, 2024 | OpenProject is the leading open source project management software. OpenProject utilizes `tablesorter` inside of the Cos... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now