2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25867 | CRITICAL | 9.1 | 0.7% | Feb 28, 2024 | A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute... |
| CVE-2024-25866 | HIGH | 8.8 | 0.8% | Feb 28, 2024 | A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute... |
| CVE-2024-25351 | LOW | 3.8 | 0.4% | Feb 28, 2024 | SQL Injection vulnerability in /zms/admin/changeimage.php in PHPGurukul Zoo Management System 1.0 allows attackers to ru... |
| CVE-2024-25350 | CRITICAL | 9.8 | 0.6% | Feb 28, 2024 | SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tpr... |
| CVE-2024-22983 | HIGH | 8.1 | 0.9% | Feb 28, 2024 | SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate... |
| CVE-2024-1972 | MEDIUM | 5.4 | 0.5% | Feb 28, 2024 | A vulnerability was found in SourceCodester Online Job Portal 1.0 and classified as problematic. Affected by this issue ... |
| CVE-2024-27285 | MEDIUM | 6.1 | 1.1% | Feb 28, 2024 | YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to... |
| CVE-2024-25859 | HIGH | 7.1 | 0.3% | Feb 28, 2024 | A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover u... |
| CVE-2024-25435 | MEDIUM | 6.1 | 0.4% | Feb 28, 2024 | A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scri... |
| CVE-2024-25202 | MEDIUM | 6.1 | 1.0% | Feb 28, 2024 | Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attacke... |
| CVE-2024-25170 | CRITICAL | 9.1 | 0.9% | Feb 28, 2024 | An issue in Mezzanine v6.0.0 allows attackers to bypass access controls via manipulating the Host header. |
| CVE-2024-25169 | CRITICAL | 9.8 | 1.1% | Feb 28, 2024 | An issue in Mezzanine v6.0.0 allows attackers to bypass access control mechanisms in the admin panel via a crafted reque... |
| CVE-2024-24148 | HIGH | 7.5 | 0.6% | Feb 28, 2024 | A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service... |
| CVE-2024-27948 | HIGH | 8.8 | 0.2% | Feb 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in bytesforall Atahualpa.This issue affects Atahualpa: from n/a through ... |
| CVE-2024-27103 | MEDIUM | 6.1 | 0.4% | Feb 28, 2024 | Querybook is a Big Data Querying UI. When a user searches for their queries, datadocs, tables and lists, the search resu... |
| CVE-2024-26342 | HIGH | 7.5 | 0.9% | Feb 28, 2024 | A Null pointer dereference in usr/sbin/httpd in ASUS AC68U 3.0.0.4.384.82230 allows remote attackers to trigger DoS via ... |
| CVE-2024-1847 | HIGH | 7.8 | 0.3% | Feb 28, 2024 | Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Typ... |
| CVE-2024-21749 | HIGH | 8.8 | 0.2% | Feb 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au 1 click disable all.This issue affects 1 click disable all:... |
| CVE-2024-0560 | MEDIUM | 4.3 | 0.5% | Feb 28, 2024 | A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is us... |
| CVE-2024-24705 | MEDIUM | 5.4 | 0.2% | Feb 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Octa Code Accessibility.This issue affects Accessibility: from n/a th... |
| CVE-2024-24702 | HIGH | 8.8 | 0.2% | Feb 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Matt Martz & Andy Stratton Page Restrict.This issue affects Page Rest... |
| CVE-2024-27515 | HIGH | 7.2 | 0.6% | Feb 28, 2024 | Osclass 5.1.2 is vulnerable to SQL Injection. |
| CVE-2024-25927 | CRITICAL | 9.8 | 0.6% | Feb 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Joel Starnes postM... |
| CVE-2024-25910 | CRITICAL | 9.8 | 0.6% | Feb 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo... |
| CVE-2024-25902 | HIGH | 7.2 | 0.5% | Feb 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now