2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-31823CRITICAL9.8An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker ...
CVE-2024-31822CRITICAL9.8An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker ...
CVE-2024-31821HIGH8SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows...
CVE-2024-31820CRITICAL9.8An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker ...
CVE-2024-31705CRITICAL9.8An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insuffici...
CVE-2024-28320HIGH7.6Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate ...
CVE-2024-33449CRITICAL9.8An SSRF issue in the PDFMyURL service allows a remote attacker to obtain sensitive information and execute arbitrary cod...
CVE-2024-33445CRITICAL9.8An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugin...
CVE-2024-33444CRITICAL9.8SQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to th...
CVE-2024-32493HIGH8.8An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able ...
CVE-2024-32492HIGH7.1An issue was discovered in Znuny 7.0.1 through 7.0.16 where the ticket detail view in the customer front allows the exec...
CVE-2024-32491CRITICAL9.8An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in use...
CVE-2024-32269HIGH7.5An issue in Yonganda YAD-LOJ V3.0.561 allows a remote attacker to cause a denial of service via a crafted packet.
CVE-2024-31621HIGH7.6An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted sc...
CVE-2024-34020MEDIUM6.5A stack-based buffer overflow was found in the putSDN() function of mail.c in hcode through 2.1.
CVE-2024-34011MEDIUM6.8Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec...
CVE-2024-34010HIGH8.2Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber...
CVE-2024-32268LOW3.3An issue in Tuya Smart camera U6N v.3.2.5 allows a remote attacker to cause a denial of service via a crafted packet to ...
CVE-2024-23995MEDIUM6.1Cross Site Scripting (XSS) in Beekeeper Studio 4.1.13 and earlier allows remote attackers to execute arbitrary code in t...
CVE-2024-1969HIGH8.2Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Secomea GateManager (webserver m...
CVE-2024-1579HIGH8.1Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Secomea GateManager (Webserver module...
CVE-2024-4310MEDIUM5.4Cross-site Scripting (XSS) vulnerability in HubBank affecting version 1.0.2. This vulnerability allows an attacker to se...
CVE-2024-4309HIGH8.1SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a spe...
CVE-2024-4308HIGH8.1SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a spe...
CVE-2024-4307HIGH8.1SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a spe...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now