2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-10397HIGH7.8A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code.
CVE-2024-10394HIGH7.8A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing th...
CVE-2024-3760HIGH7.5In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bom...
CVE-2024-5125HIGH7.3parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input ...
CVE-2024-52396HIGH8.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-edi...
CVE-2024-52393HIGH7.2Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-...
CVE-2024-52383HIGH7.5Missing Authorization vulnerability in aitool Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in On...
CVE-2024-52381HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-52378HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 DigiPass digipass...
CVE-2024-52371HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DonnellC Global Gateway ...
CVE-2024-50831HIGH7.2A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the usernam...
CVE-2024-50830HIGH7.2A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Proje...
CVE-2024-50829HIGH7.2A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0...
CVE-2024-50828HIGH7.2A SQL Injection vulnerability was found in /admin/edit_department.php in kashipara E-learning Management System Project ...
CVE-2024-50827HIGH7.2A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 ...
CVE-2024-50826HIGH7.2A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 ...
CVE-2024-50825HIGH7.2A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 ...
CVE-2024-50824HIGH7.2A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via th...
CVE-2024-3502HIGH8.1In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists where account rec...
CVE-2024-3501HIGH8.1In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclus...
CVE-2024-3379HIGH8.1In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to ...
CVE-2024-6068HIGH7.3A memory corruption vulnerability exists in the affected products when parsing DFT files. Local threat actors can explo...
CVE-2024-50835HIGH7.2A SQL Injection vulnerability was found in /admin/edit_student.php in KASHIPARA E-learning Management System Project 1.0...
CVE-2024-50834HIGH7.2A SQL Injection was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0 via the firstname...
CVE-2024-50832HIGH7.2A SQL Injection vulnerability was found in /admin/edit_class.php in kashipara E-learning Management System Project 1.0 v...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now