2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25533 | CRITICAL | 9.4 | 0.7% | May 8, 2024 | Error messages in RuvarOA v6.01 and v12.01 were discovered to leak the physical path of the website (/WorkFlow/OfficeFil... |
| CVE-2024-25532 | CRITICAL | 9.8 | 0.5% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the bt_id parameter at /include/ge... |
| CVE-2024-31961 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | A SQL injection vulnerability in unit.php in Sonic Shopfloor.guide before 3.1.3 allows remote attackers to execute arbit... |
| CVE-2024-25531 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtilit... |
| CVE-2024-25530 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the PageID parameter at /WebUtilit... |
| CVE-2024-25529 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /WorkFlow/wf_o... |
| CVE-2024-25527 | CRITICAL | 9.4 | 0.5% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffai... |
| CVE-2024-4654 | CRITICAL | 9.8 | 0.8% | May 8, 2024 | A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This... |
| CVE-2024-32980 | CRITICAL | 9.1 | 0.5% | May 8, 2024 | Spin is the developer tool for building and running serverless applications powered by WebAssembly. Prior to 2.4.3, some... |
| CVE-2024-32113 | CRITICAL | 9.8 | 99.4% | May 8, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue ... |
| CVE-2024-26579 | CRITICAL | 9.8 | 1.1% | May 8, 2024 | Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.... |
| CVE-2024-25525 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the filename parameter at /WorkFlo... |
| CVE-2024-25524 | CRITICAL | 9.4 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter ... |
| CVE-2024-25523 | CRITICAL | 9.8 | 0.7% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemana... |
| CVE-2024-25522 | CRITICAL | 9.4 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the office_missive_id parameter at... |
| CVE-2024-25521 | CRITICAL | 9.4 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the txt_keyword parameter at get_c... |
| CVE-2024-25520 | CRITICAL | 9.8 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys... |
| CVE-2024-25519 | CRITICAL | 9.8 | 0.7% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/... |
| CVE-2024-25518 | CRITICAL | 9.4 | 0.6% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /Work... |
| CVE-2024-25517 | CRITICAL | 9.8 | 0.7% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtilit... |
| CVE-2024-4393 | CRITICAL | 9.8 | 0.8% | May 8, 2024 | The Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2. Th... |
| CVE-2024-34346 | CRITICAL | 9 | 0.4% | May 7, 2024 | Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. The Deno sandbox may be unexpectedly wea... |
| CVE-2024-4558 | CRITICAL | 9.6 | 1.3% | May 7, 2024 | Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap c... |
| CVE-2024-25514 | CRITICAL | 9.4 | 0.6% | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /SysM... |
| CVE-2024-25511 | CRITICAL | 9.4 | 0.6% | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now