2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-24774MEDIUM4.1Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based o...
CVE-2024-23319LOW3.5Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message tha...
CVE-2024-25318HIGH8.8Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'pid' parameter in Hotel/admin/print.php?pid=2.
CVE-2024-25316CRITICAL9.8Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?...
CVE-2024-25315CRITICAL9.8Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2...
CVE-2024-25314CRITICAL9.8Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2.
CVE-2024-25310HIGH8.8Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5....
CVE-2024-25307CRITICAL9.8Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/boo...
CVE-2024-25302CRITICAL9.8Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.
CVE-2024-25313HIGH8.8Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters a...
CVE-2024-25312HIGH8.8Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?i...
CVE-2024-25309HIGH8.8Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.p...
CVE-2024-25308HIGH8.8Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.p...
CVE-2024-25306HIGH8.8Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'aname' parameter at "School/index.php".
CVE-2024-25305HIGH8.8Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters a...
CVE-2024-25304HIGH8.8Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'apass' parameter at "School/index.php."
CVE-2024-25679MEDIUM6.5In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK...
CVE-2024-25678CRITICAL9.8In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
CVE-2024-25677HIGH8.8In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly ...
CVE-2024-25675CRITICAL9.8An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process...
CVE-2024-25674CRITICAL9.8An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the...
CVE-2024-22119MEDIUM5.4The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.
CVE-2024-21762CRITICAL9.8A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0...
CVE-2024-24308CRITICAL9.8SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows re...
CVE-2024-23749HIGH7.8KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insuffic...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now