2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34314 | MEDIUM | 4.9 | 0.4% | May 7, 2024 | CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the... |
| CVE-2024-25514 | CRITICAL | 9.4 | 0.6% | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /SysM... |
| CVE-2024-25513 | HIGH | 7.8 | 0.3% | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /Corporat... |
| CVE-2024-25511 | CRITICAL | 9.4 | 0.6% | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/a... |
| CVE-2024-25510 | CRITICAL | 9.8 | 0.7% | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/a... |
| CVE-2024-25509 | CRITICAL | 9.4 | 0.6% | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter ... |
| CVE-2024-34517 | MEDIUM | 6.5 | 0.6% | May 7, 2024 | The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al... |
| CVE-2024-34397 | MEDIUM | 5.2 | 0.8% | May 7, 2024 | An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subs... |
| CVE-2024-25512 | HIGH | 8.1 | 0.5% | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the attach_id parameter at /Bullet... |
| CVE-2024-25508 | CRITICAL | 9.8 | 0.7% | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /bulletin/bull... |
| CVE-2024-25507 | CRITICAL | 9.4 | 0.6% | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the email_attach_id parameter at /... |
| CVE-2024-33860 | MEDIUM | 6.5 | 0.4% | May 7, 2024 | An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is us... |
| CVE-2024-33859 | MEDIUM | 6.1 | 0.3% | May 7, 2024 | An issue was discovered in Logpoint before 7.4.0. HTML code sent through logs wasn't being escaped in the "Interesting F... |
| CVE-2024-33164 | CRITICAL | 9.8 | 0.6% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList... |
| CVE-2024-33161 | MEDIUM | 5.3 | 0.2% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedL... |
| CVE-2024-33155 | CRITICAL | 9.8 | 0.6% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList(... |
| CVE-2024-33153 | CRITICAL | 9.8 | 0.6% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the commentList(... |
| CVE-2024-33149 | HIGH | 8.1 | 0.5% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessLis... |
| CVE-2024-33148 | HIGH | 7.3 | 0.4% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list functio... |
| CVE-2024-33147 | HIGH | 8.8 | 0.5% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authRoleList... |
| CVE-2024-29210 | LOW | 2.8 | 0.2% | May 7, 2024 | A local privilege escalation (LPE) vulnerability has been identified in Phish Alert Button for Outlook (PAB), specifical... |
| CVE-2024-29209 | MEDIUM | 6 | 0.4% | May 7, 2024 | A medium severity vulnerability has been identified in the update mechanism of the Phish Alert Button for Outlook, which... |
| CVE-2024-29208 | LOW | 2.2 | 0.3% | May 7, 2024 | An Unverified Password Change could allow a malicious actor with API access to the device to change the system password ... |
| CVE-2024-29207 | HIGH | 7.5 | 0.3% | May 7, 2024 | An Improper Certificate Validation could allow a malicious actor with access to an adjacent network to take control of t... |
| CVE-2024-29206 | LOW | 2.2 | 0.4% | May 7, 2024 | An Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now