2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25510 | CRITICAL | 9.8 | 0.7% | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/a... |
| CVE-2024-25509 | CRITICAL | 9.4 | 0.6% | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter ... |
| CVE-2024-25508 | CRITICAL | 9.8 | 0.7% | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /bulletin/bull... |
| CVE-2024-25507 | CRITICAL | 9.4 | 0.6% | May 7, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the email_attach_id parameter at /... |
| CVE-2024-33164 | CRITICAL | 9.8 | 0.6% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList... |
| CVE-2024-33155 | CRITICAL | 9.8 | 0.6% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList(... |
| CVE-2024-33153 | CRITICAL | 9.8 | 0.6% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the commentList(... |
| CVE-2024-33857 | CRITICAL | 9.6 | 0.4% | May 7, 2024 | An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in threat intelligence, an a... |
| CVE-2024-33146 | CRITICAL | 9.1 | 0.5% | May 7, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export funct... |
| CVE-2024-33124 | CRITICAL | 9.8 | 0.5% | May 7, 2024 | Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() fun... |
| CVE-2024-33120 | CRITICAL | 9.8 | 0.8% | May 7, 2024 | Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload... |
| CVE-2024-32370 | CRITICAL | 9.8 | 1.0% | May 7, 2024 | An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive info... |
| CVE-2024-33434 | CRITICAL | 9.8 | 1.4% | May 7, 2024 | An issue in tiagorlampert CHAOS v5.0.1 before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae... |
| CVE-2024-4346 | CRITICAL | 9.1 | 1.5% | May 7, 2024 | The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and ... |
| CVE-2024-4345 | CRITICAL | 9.8 | 1.4% | May 7, 2024 | The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file typ... |
| CVE-2024-4186 | CRITICAL | 9.8 | 0.9% | May 7, 2024 | The Edwiser Bridge plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.5. ... |
| CVE-2024-34532 | CRITICAL | 9.8 | 0.7% | May 6, 2024 | A SQL injection vulnerability in Yvan Dotet PostgreSQL Query Deluxe module (aka query_deluxe) 17.x before 17.0.0.4 allow... |
| CVE-2024-33411 | CRITICAL | 9.8 | 0.7% | May 6, 2024 | A SQL injection vulnerability in /model/get_admin_profile.php in Campcodes Complete Web-Based School Management System 1... |
| CVE-2024-33409 | CRITICAL | 9.8 | 0.7% | May 6, 2024 | SQL injection vulnerability in index.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to... |
| CVE-2024-33408 | CRITICAL | 9.8 | 0.7% | May 6, 2024 | A SQL injection vulnerability in /model/get_classroom.php in campcodes Complete Web-Based School Management System 1.0 a... |
| CVE-2024-33403 | CRITICAL | 9.8 | 0.7% | May 6, 2024 | A SQL injection vulnerability in /model/get_events.php in campcodes Complete Web-Based School Management System 1.0 allo... |
| CVE-2024-34249 | CRITICAL | 9.8 | 0.7% | May 6, 2024 | wasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation fault via the function "Deallo... |
| CVE-2024-33294 | CRITICAL | 9.1 | 0.7% | May 6, 2024 | An issue in Library System using PHP/MySQli with Source Code V1.0 allows a remote attacker to execute arbitrary code via... |
| CVE-2024-33110 | CRITICAL | 9.1 | 0.7% | May 6, 2024 | D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component. |
| CVE-2024-21480 | CRITICAL | 9.8 | 0.3% | May 6, 2024 | Memory corruption while playing audio file having large-sized input buffer. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now