2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25223CRITICAL9.8Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminV...
CVE-2024-25222CRITICAL9.8Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManage...
CVE-2024-25221MEDIUM6.1A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or...
CVE-2024-25220CRITICAL9.8Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/E...
CVE-2024-25219MEDIUM6.1A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or...
CVE-2024-25218MEDIUM6.1A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or...
CVE-2024-25217CRITICAL9.8Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /om...
CVE-2024-25216CRITICAL9.8Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /apro...
CVE-2024-25215CRITICAL9.8Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aproces...
CVE-2024-25214CRITICAL9.8An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload int...
CVE-2024-25213HIGH7.2Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php...
CVE-2024-25212HIGH7.2Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.p...
CVE-2024-25211CRITICAL9.8Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpo...
CVE-2024-25210CRITICAL9.8Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoi...
CVE-2024-25209CRITICAL9.8Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident param...
CVE-2024-25208MEDIUM5.4Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the A...
CVE-2024-25207MEDIUM5.4Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the A...
CVE-2024-23952MEDIUM6.5This is a duplicate for CVE-2023-46104. With correct CVE version ranges for affected Apache Superset. Uncontrolled res...
CVE-2024-23789HIGH8.8Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent una...
CVE-2024-23788HIGH8.1Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1....
CVE-2024-23787MEDIUM6.5Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earli...
CVE-2024-23786CRITICAL9.3Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and...
CVE-2024-23785MEDIUM6.5Cross-site request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9...
CVE-2024-23784MEDIUM6.5Improper access control vulnerability exists in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0...
CVE-2024-23783HIGH8.8Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now