2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-48392 | MEDIUM | 5.4 | 0.8% | Jan 21, 2025 | OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into u... |
| CVE-2024-21245 | MEDIUM | 5.4 | 0.2% | Jan 21, 2025 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). ... |
| CVE-2024-42936 | CRITICAL | 9.8 | 1.0% | Jan 21, 2025 | The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Ex... |
| CVE-2024-55504 | MEDIUM | 5.5 | 0.5% | Jan 21, 2025 | An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially ... |
| CVE-2024-51417 | MEDIUM | 6.4 | 0.3% | Jan 21, 2025 | An issue in System.Linq.Dynamic.Core before 1.6.0 allows remote access to properties on reflection types and static prop... |
| CVE-2024-54795 | MEDIUM | 5.4 | 0.5% | Jan 21, 2025 | SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the works... |
| CVE-2024-54794 | CRITICAL | 9.1 | 12.7% | Jan 21, 2025 | The script input feature of SpagoBI 3.5.1 allows arbitrary code execution. |
| CVE-2024-54792 | MEDIUM | 6.1 | 0.3% | Jan 21, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An ... |
| CVE-2024-45687 | LOW | 2.4 | 0.2% | Jan 21, 2025 | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in Payara Pl... |
| CVE-2024-57036 | HIGH | 8.1 | 0.5% | Jan 21, 2025 | TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main f... |
| CVE-2024-56990 | MEDIUM | 4.5 | 0.4% | Jan 21, 2025 | PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /view-medhistory.php and /admin... |
| CVE-2024-56998 | MEDIUM | 4.2 | 0.2% | Jan 21, 2025 | PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /edit-profile.php via the param... |
| CVE-2024-56997 | MEDIUM | 4.2 | 0.2% | Jan 21, 2025 | PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /doctor/index.php via the 'Emai... |
| CVE-2024-53829 | HIGH | 8.2 | 0.2% | Jan 21, 2025 | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ... |
| CVE-2024-56277 | MEDIUM | 5.3 | 0.3% | Jan 21, 2025 | Improper Encoding or Escaping of Output vulnerability in Ays Pro Poll Maker poll-maker.This issue affects Poll Maker: fr... |
| CVE-2024-51919 | CRITICAL | 9 | 0.5% | Jan 21, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in radykal Fancy Product Designer fancy-product-designer.T... |
| CVE-2024-51888 | CRITICAL | 9.8 | 0.4% | Jan 21, 2025 | Incorrect Privilege Assignment vulnerability in favethemes Homey Login Register homey-login-register allows Privilege Es... |
| CVE-2024-51818 | CRITICAL | 9.3 | 15.5% | Jan 21, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in radykal Fancy Prod... |
| CVE-2024-49700 | HIGH | 7.1 | 0.3% | Jan 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reputeinfosystems ... |
| CVE-2024-49699 | HIGH | 8.8 | 0.8% | Jan 21, 2025 | Deserialization of Untrusted Data vulnerability in reputeinfosystems ARPrice arprice allows Object Injection.This issue ... |
| CVE-2024-49688 | CRITICAL | 9.8 | 0.4% | Jan 21, 2025 | Deserialization of Untrusted Data vulnerability in reputeinfosystems ARPrice arprice allows Object Injection.This issue ... |
| CVE-2024-49666 | HIGH | 8.5 | 0.4% | Jan 21, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems ... |
| CVE-2024-49655 | CRITICAL | 9.3 | 0.3% | Jan 21, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems ... |
| CVE-2024-49333 | HIGH | 8.5 | 0.4% | Jan 21, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Hero Mega... |
| CVE-2024-49303 | HIGH | 8.5 | 0.4% | Jan 21, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Hero Mega... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now