2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-2076HIGH7.5A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as problematic. Affected by...
CVE-2024-1453HIGH7.8 In Sante DICOM Viewer Pro versions 14.0.3 and prior, a user must open a malicious DICOM file, which could allow a local...
CVE-2024-2075MEDIUM5.4A vulnerability was found in SourceCodester Daily Habit Tracker 1.0. It has been declared as problematic. Affected by th...
CVE-2024-2074MEDIUM6.3A vulnerability was found in Mini-Tmall up to 20231017 and classified as critical. This issue affects some unknown proce...
CVE-2024-27298CRITICAL10parse-server is a Parse Server for Node.js / Express. This vulnerability allows SQL injection when Parse Server is confi...
CVE-2024-2073HIGH8.8A vulnerability has been found in SourceCodester Block Inserter for Dynamic Content 1.0 and classified as critical. This...
CVE-2024-2072MEDIUM5.4A vulnerability, which was classified as problematic, was found in SourceCodester Flashcard Quiz App 1.0. This affects a...
CVE-2024-2071MEDIUM5.4A vulnerability, which was classified as problematic, has been found in SourceCodester FAQ Management System 1.0. Affect...
CVE-2024-27734MEDIUM6.1A Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows an attacker to execute arbitrary code via a crafted scrip...
CVE-2024-27692Rejected reason: * REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-22939. Reason: This candidate is a d...
CVE-2024-27689HIGH8.8Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via /update-article.php.
CVE-2024-27559MEDIUM6.3Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings....
CVE-2024-27558MEDIUM6.1Stupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings.
CVE-2024-2070MEDIUM6.1A vulnerability classified as problematic was found in SourceCodester FAQ Management System 1.0. Affected by this vulner...
CVE-2024-2069MEDIUM5.3A vulnerability classified as critical has been found in SourceCodester FAQ Management System 1.0. Affected is an unknow...
CVE-2024-2068MEDIUM6.1A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been rated as problematic. This issue ...
CVE-2024-27499MEDIUM6.5Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.
CVE-2024-27296MEDIUM5.3Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 10.8.3, the exact Dire...
CVE-2024-27295HIGH8.2Directus is a real-time API and App dashboard for managing SQL database content. The password reset mechanism of the Dir...
CVE-2024-27140MEDIUM5.4** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vu...
CVE-2024-27139HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Arch...
CVE-2024-27138HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting t...
CVE-2024-1624CRITICAL9.4An OS Command Injection vulnerability affecting documentation server on 3DEXPERIENCE from Release 3DEXPERIENCE R2022x th...
CVE-2024-2067CRITICAL9.8A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been declared as critical. This vulner...
CVE-2024-2066MEDIUM6.1A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been classified as problematic. This a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now