2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5314 | CRITICAL | 9.1 | 0.6% | May 24, 2024 | Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could all... |
| CVE-2024-4544 | CRITICAL | 9.8 | 0.6% | May 24, 2024 | The Pie Register - Social Sites Login (Add on) plugin for WordPress is vulnerable to authentication bypass in versions u... |
| CVE-2024-5296 | CRITICAL | 9.8 | 1.1% | May 23, 2024 | D-Link D-View Use of Hard-coded Cryptographic Key Authentication Bypass Vulnerability. This vulnerability allows remote ... |
| CVE-2024-35570 | CRITICAL | 9.8 | 0.9% | May 23, 2024 | An arbitrary file upload vulnerability in the component \controller\ImageUploadController.class of inxedu v2.0.6 allows ... |
| CVE-2024-35375 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.... |
| CVE-2024-35080 | CRITICAL | 9.8 | 0.6% | May 23, 2024 | An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code v... |
| CVE-2024-35079 | CRITICAL | 9.8 | 0.6% | May 23, 2024 | An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary... |
| CVE-2024-35091 | CRITICAL | 9.8 | 0.4% | May 23, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml... |
| CVE-2024-35086 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in BpmTaskFromMapper.x... |
| CVE-2024-35084 | CRITICAL | 9.8 | 0.4% | May 23, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysMsgPushMapper.xm... |
| CVE-2024-34935 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | A SQL injection vulnerability in /view/conversation_history_admin.php in Campcodes Complete Web-Based School Management ... |
| CVE-2024-34934 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | A SQL injection vulnerability in /view/emarks_range_grade_update_form.php in Campcodes Complete Web-Based School Managem... |
| CVE-2024-34932 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | A SQL injection vulnerability in /model/update_exam.php in Campcodes Complete Web-Based School Management System 1.0 all... |
| CVE-2024-34931 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | A SQL injection vulnerability in /model/update_subject.php in Campcodes Complete Web-Based School Management System 1.0 ... |
| CVE-2024-34929 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | A SQL injection vulnerability in /view/find_friends.php in Campcodes Complete Web-Based School Management System 1.0 all... |
| CVE-2024-34927 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | A SQL injection vulnerability in /model/update_classroom.php in Campcodes Complete Web-Based School Management System 1.... |
| CVE-2024-5085 | CRITICAL | 9.8 | 0.8% | May 23, 2024 | The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up t... |
| CVE-2024-5084 | CRITICAL | 9.8 | 50.9% | May 23, 2024 | The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing fil... |
| CVE-2024-5168 | CRITICAL | 9.8 | 0.5% | May 23, 2024 | Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerabi... |
| CVE-2024-4399 | CRITICAL | 9.1 | 1.8% | May 23, 2024 | The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSR... |
| CVE-2024-29849 | CRITICAL | 9.8 | 16.7% | May 22, 2024 | Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface. |
| CVE-2024-4267 | CRITICAL | 9.8 | 1.5% | May 22, 2024 | A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' mod... |
| CVE-2024-25738 | CRITICAL | 9.1 | 0.7% | May 22, 2024 | A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0... |
| CVE-2024-33226 | CRITICAL | 9.9 | 0.4% | May 22, 2024 | An issue in the component Access64.sys of Wistron Corporation TBT Force Power Control v1.0.0.0 allows attackers to escal... |
| CVE-2024-35409 | CRITICAL | 9.8 | 0.5% | May 22, 2024 | WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now