2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0849MEDIUM5Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to ...
CVE-2024-1269MEDIUM6.1A vulnerability has been found in SourceCodester Product Management System 1.0 and classified as problematic. This vulne...
CVE-2024-1268CRITICAL9.8A vulnerability, which was classified as critical, was found in CodeAstro Restaurant POS System 1.0. This affects an unk...
CVE-2024-24019CRITICAL9.8A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset...
CVE-2024-22022HIGH8.8Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to a...
CVE-2024-22021MEDIUM4.3Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retri...
CVE-2024-1267MEDIUM6.1A vulnerability, which was classified as problematic, has been found in CodeAstro Restaurant POS System 1.0. Affected by...
CVE-2024-1266MEDIUM6.1A vulnerability classified as problematic was found in CodeAstro University Management System 1.0. Affected by this vuln...
CVE-2024-24004CRITICAL9.8jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseRespon...
CVE-2024-24002CRITICAL9.8jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseRespons...
CVE-2024-24001CRITICAL9.8jshERP v3.3 is vulnerable to SQL Injection. via the com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseRe...
CVE-2024-1284CRITICAL9.8Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap co...
CVE-2024-1283CRITICAL9.8Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit h...
CVE-2024-1265MEDIUM4.8A vulnerability classified as problematic has been found in CodeAstro University Management System 1.0. Affected is an u...
CVE-2024-1264CRITICAL9.8A vulnerability has been found in Juanpao JPShop up to 1.5.02 and classified as critical. Affected by this vulnerability...
CVE-2024-0971MEDIUM6.5 A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter sca...
CVE-2024-0955MEDIUM4.8 A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus a...
CVE-2024-24255MEDIUM4.2A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allows...
CVE-2024-22388HIGH7.8Certain configuration available in the communication channel for encoders could expose sensitive data when reader config...
CVE-2024-1263CRITICAL9.8A vulnerability, which was classified as critical, was found in Juanpao JPShop up to 1.5.02. Affected is the function ac...
CVE-2024-1262CRITICAL9.8A vulnerability, which was classified as critical, has been found in Juanpao JPShop up to 1.5.02. This issue affects the...
CVE-2024-24680HIGH7.5An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma templa...
CVE-2024-24577CRITICAL9.8libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing...
CVE-2024-24575HIGH7.5libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing...
CVE-2024-24254MEDIUM4.2PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now