2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31546 | CRITICAL | 9.8 | 0.7% | Apr 19, 2024 | Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/damage/view_d... |
| CVE-2024-32644 | CRITICAL | 9.1 | 0.9% | Apr 19, 2024 | Evmos is a scalable, high-throughput Proof-of-Stake EVM blockchain that is fully compatible and interoperable with Ether... |
| CVE-2024-32038 | CRITICAL | 9.8 | 1.0% | Apr 19, 2024 | Wazuh is a free and open source platform used for threat prevention, detection, and response. There is a buffer overflow... |
| CVE-2024-29966 | CRITICAL | 9.8 | 0.7% | Apr 19, 2024 | Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appl... |
| CVE-2024-29204 | CRITICAL | 9.8 | 4.3% | Apr 19, 2024 | A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthent... |
| CVE-2024-24996 | CRITICAL | 9.8 | 32.2% | Apr 19, 2024 | A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated ... |
| CVE-2024-22061 | CRITICAL | 9.8 | 3.6% | Apr 19, 2024 | A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenti... |
| CVE-2024-31750 | CRITICAL | 9.8 | 19.4% | Apr 19, 2024 | SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the ... |
| CVE-2024-30938 | CRITICAL | 9.8 | 0.8% | Apr 19, 2024 | SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID paramete... |
| CVE-2024-30923 | CRITICAL | 9.8 | 1.4% | Apr 18, 2024 | SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where ... |
| CVE-2024-30922 | CRITICAL | 9.8 | 1.4% | Apr 18, 2024 | SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in ... |
| CVE-2024-30564 | CRITICAL | 9.8 | 1.2% | Apr 18, 2024 | An issue inandrei-tatar nora-firebase-common between v.1.0.41 and v.1.12.2 allows a remote attacker to execute arbitrary... |
| CVE-2024-2796 | CRITICAL | 9.3 | 0.4% | Apr 18, 2024 | A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.... |
| CVE-2024-29021 | CRITICAL | 9 | 20.2% | Apr 18, 2024 | Judge0 is an open-source online code execution system. The default configuration of Judge0 leaves the service vulnerable... |
| CVE-2024-28189 | CRITICAL | 10 | 7.2% | Apr 18, 2024 | Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file ... |
| CVE-2024-28185 | CRITICAL | 10 | 7.1% | Apr 18, 2024 | Judge0 is an open-source online code execution system. The application does not account for symlinks placed inside the s... |
| CVE-2024-3948 | CRITICAL | 9.8 | 0.9% | Apr 18, 2024 | A vulnerability was found in SourceCodester Home Clean Service System 1.0. It has been rated as critical. Affected by th... |
| CVE-2024-32600 | CRITICAL | 9.6 | 0.5% | Apr 18, 2024 | Deserialization of Untrusted Data vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a throu... |
| CVE-2024-32599 | CRITICAL | 10 | 0.7% | Apr 18, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Deepak anand WP Dummy Content Generator wp-du... |
| CVE-2024-32340 | CRITICAL | 9.6 | 0.7% | Apr 17, 2024 | A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbit... |
| CVE-2024-3817 | CRITICAL | 9.8 | 1.3% | Apr 17, 2024 | HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This... |
| CVE-2024-21990 | CRITICAL | 9.8 | 0.3% | Apr 17, 2024 | ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that... |
| CVE-2024-31581 | CRITICAL | 9.8 | 1.1% | Apr 17, 2024 | FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266... |
| CVE-2024-30990 | CRITICAL | 9.8 | 0.6% | Apr 17, 2024 | SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows a... |
| CVE-2024-32161 | CRITICAL | 9.8 | 0.7% | Apr 17, 2024 | jizhiCMS 2.5 suffers from a File upload vulnerability. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now