2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25867CRITICAL9.1A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute...
CVE-2024-25866HIGH8.8A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute...
CVE-2024-25351LOW3.8SQL Injection vulnerability in /zms/admin/changeimage.php in PHPGurukul Zoo Management System 1.0 allows attackers to ru...
CVE-2024-25350CRITICAL9.8SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tpr...
CVE-2024-22983HIGH8.1SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate...
CVE-2024-1972MEDIUM5.4A vulnerability was found in SourceCodester Online Job Portal 1.0 and classified as problematic. Affected by this issue ...
CVE-2024-27285MEDIUM6.1YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to...
CVE-2024-25859HIGH7.1A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover u...
CVE-2024-25435MEDIUM6.1A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scri...
CVE-2024-25202MEDIUM6.1Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attacke...
CVE-2024-25170CRITICAL9.1An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header.
CVE-2024-25169CRITICAL9.8An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted reque...
CVE-2024-24148HIGH7.5A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service...
CVE-2024-27948HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in bytesforall Atahualpa.This issue affects Atahualpa: from n/a through ...
CVE-2024-27103MEDIUM6.1Querybook is a Big Data Querying UI. When a user searches for their queries, datadocs, tables and lists, the search resu...
CVE-2024-26342HIGH7.5A Null pointer dereference in usr/sbin/httpd in ASUS AC68U 3.0.0.4.384.82230 allows remote attackers to trigger DoS via ...
CVE-2024-1847HIGH7.8Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Typ...
CVE-2024-21749HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au 1 click disable all.This issue affects 1 click disable all:...
CVE-2024-0560MEDIUM4.3A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is us...
CVE-2024-24705MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Octa Code Accessibility.This issue affects Accessibility: from n/a th...
CVE-2024-24702HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Matt Martz & Andy Stratton Page Restrict.This issue affects Page Rest...
CVE-2024-27515HIGH7.2Osclass 5.1.2 is vulnerable to SQL Injection.
CVE-2024-25927CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Joel Starnes postM...
CVE-2024-25910CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo...
CVE-2024-25902HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now