2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-27280 | CRITICAL | 9.8 | 2.4% | May 14, 2024 | A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3... |
| CVE-2024-26517 | CRITICAL | 9.1 | 0.8% | May 14, 2024 | SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a ... |
| CVE-2024-23473 | CRITICAL | 9.8 | 1.1% | May 14, 2024 | The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. I... |
| CVE-2024-34257 | CRITICAL | 9.8 | 3.8% | May 8, 2024 | TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized e... |
| CVE-2024-25533 | CRITICAL | 9.4 | 0.7% | May 8, 2024 | Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFil... |
| CVE-2024-25532 | CRITICAL | 9.8 | 0.5% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/ge... |
| CVE-2024-31961 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | A SQL injection vulnerability in unit.php in Sonic Shopfloor.guide before 3.1.3 allows remote attackers to execute arbit... |
| CVE-2024-25531 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtilit... |
| CVE-2024-25530 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtilit... |
| CVE-2024-25529 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_o... |
| CVE-2024-25527 | CRITICAL | 9.4 | 0.5% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffai... |
| CVE-2024-4654 | CRITICAL | 9.8 | 0.8% | May 8, 2024 | A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This... |
| CVE-2024-32980 | CRITICAL | 9.1 | 0.5% | May 8, 2024 | Spin is the developer tool for building and running serverless applications powered by WebAssembly. Prior to 2.4.3, some... |
| CVE-2024-32113 | CRITICAL | 9.8 | 99.4% | May 8, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue ... |
| CVE-2024-26579 | CRITICAL | 9.8 | 1.1% | May 8, 2024 | Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.... |
| CVE-2024-25525 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlo... |
| CVE-2024-25524 | CRITICAL | 9.4 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter ... |
| CVE-2024-25523 | CRITICAL | 9.8 | 0.7% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemana... |
| CVE-2024-25522 | CRITICAL | 9.4 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the office_missive_id parameter at... |
| CVE-2024-25521 | CRITICAL | 9.4 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the txt_keyword parameter at get_c... |
| CVE-2024-25520 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys... |
| CVE-2024-25519 | CRITICAL | 9.8 | 0.7% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/... |
| CVE-2024-25518 | CRITICAL | 9.4 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /Work... |
| CVE-2024-25517 | CRITICAL | 9.8 | 0.7% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtilit... |
| CVE-2024-4393 | CRITICAL | 9.8 | 0.8% | May 8, 2024 | The Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2. Th... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now