2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34314MEDIUM4.9CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the...
CVE-2024-25514CRITICAL9.4RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /SysM...
CVE-2024-25513HIGH7.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /Corporat...
CVE-2024-25511CRITICAL9.4RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/a...
CVE-2024-25510CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/a...
CVE-2024-25509CRITICAL9.4RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter ...
CVE-2024-34517MEDIUM6.5The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker al...
CVE-2024-34397MEDIUM5.2An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subs...
CVE-2024-25512HIGH8.1RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the attach_id parameter at /Bullet...
CVE-2024-25508CRITICAL9.8RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /bulletin/bull...
CVE-2024-25507CRITICAL9.4RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the email_attach_id parameter at /...
CVE-2024-33860MEDIUM6.5An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is us...
CVE-2024-33859MEDIUM6.1An issue was discovered in Logpoint before 7.4.0. HTML code sent through logs wasn't being escaped in the "Interesting F...
CVE-2024-33164CRITICAL9.8J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList...
CVE-2024-33161MEDIUM5.3J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedL...
CVE-2024-33155CRITICAL9.8J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList(...
CVE-2024-33153CRITICAL9.8J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the commentList(...
CVE-2024-33149HIGH8.1J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessLis...
CVE-2024-33148HIGH7.3J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list functio...
CVE-2024-33147HIGH8.8J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authRoleList...
CVE-2024-29210LOW2.8A local privilege escalation (LPE) vulnerability has been identified in Phish Alert Button for Outlook (PAB), specifical...
CVE-2024-29209MEDIUM6A medium severity vulnerability has been identified in the update mechanism of the Phish Alert Button for Outlook, which...
CVE-2024-29208LOW2.2An Unverified Password Change could allow a malicious actor with API access to the device to change the system password ...
CVE-2024-29207HIGH7.5An Improper Certificate Validation could allow a malicious actor with access to an adjacent network to take control of t...
CVE-2024-29206LOW2.2An Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now