2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29276 | CRITICAL | 9.8 | 32.8% | Apr 2, 2024 | An issue was discovered in seeyonOA version 8, allows remote attackers to execute arbitrary code via the importProcess m... |
| CVE-2024-1863 | CRITICAL | 9.8 | 1.1% | Apr 1, 2024 | Sante PACS Server Token Endpoint SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote att... |
| CVE-2024-29433 | CRITICAL | 9.8 | 0.8% | Apr 1, 2024 | A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary comman... |
| CVE-2024-30867 | CRITICAL | 9.8 | 0.7% | Apr 1, 2024 | netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_virtual_site_info.php. |
| CVE-2024-30858 | CRITICAL | 9.8 | 0.7% | Apr 1, 2024 | netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php. |
| CVE-2024-25574 | CRITICAL | 9.8 | 8.8% | Apr 1, 2024 | SQL injection vulnerability exists in GetDIAE_usListParameters. |
| CVE-2024-30865 | CRITICAL | 9.8 | 0.7% | Apr 1, 2024 | netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_user_login.php. |
| CVE-2024-21473 | CRITICAL | 9.8 | 0.7% | Apr 1, 2024 | Memory corruption while redirecting log file to any file location with any file name. |
| CVE-2024-21463 | CRITICAL | 9.8 | 0.3% | Apr 1, 2024 | Memory corruption while processing Codec2 during v13k decoder pitch synthesis. |
| CVE-2024-30868 | CRITICAL | 9.8 | 0.7% | Apr 1, 2024 | netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php. |
| CVE-2024-31115 | CRITICAL | 10 | 0.6% | Mar 31, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPres... |
| CVE-2024-31114 | CRITICAL | 9.1 | 1.4% | Mar 31, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in biplob018 Shortcode Addons.This issue affects Shortcode... |
| CVE-2024-3087 | CRITICAL | 9.8 | 0.8% | Mar 30, 2024 | A vulnerability, which was classified as critical, has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. A... |
| CVE-2024-3085 | CRITICAL | 9.8 | 0.8% | Mar 30, 2024 | A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is a... |
| CVE-2024-2086 | CRITICAL | 10 | 0.7% | Mar 30, 2024 | The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files I... |
| CVE-2024-28288 | CRITICAL | 9.8 | 0.7% | Mar 30, 2024 | Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrato... |
| CVE-2024-29667 | CRITICAL | 9.8 | 0.6% | Mar 29, 2024 | SQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote atta... |
| CVE-2024-3094 | CRITICAL | 10 | 86.0% | Mar 29, 2024 | Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex... |
| CVE-2024-31032 | CRITICAL | 9.8 | 1.1% | Mar 29, 2024 | An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacke... |
| CVE-2024-29640 | CRITICAL | 9.8 | 1.4% | Mar 29, 2024 | An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted paylo... |
| CVE-2024-30477 | CRITICAL | 9.8 | 0.5% | Mar 29, 2024 | Missing Authorization vulnerability in Klarna Klarna Payments for WooCommerce.This issue affects Klarna Payments for Woo... |
| CVE-2024-30247 | CRITICAL | 9.8 | 2.1% | Mar 29, 2024 | NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid HC1, Rock64 and other boards. A command i... |
| CVE-2024-30508 | CRITICAL | 9.8 | 0.5% | Mar 29, 2024 | Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through ... |
| CVE-2024-30502 | CRITICAL | 9.8 | 2.3% | Mar 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.T... |
| CVE-2024-29202 | CRITICAL | 9.9 | 5.9% | Mar 29, 2024 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now