2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-48392MEDIUM5.4OrangeScrum v2.0.11 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into u...
CVE-2024-21245MEDIUM5.4Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). ...
CVE-2024-42936CRITICAL9.8The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Ex...
CVE-2024-55504MEDIUM5.5An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially ...
CVE-2024-51417MEDIUM6.4An issue in System.Linq.Dynamic.Core before 1.6.0 allows remote access to properties on reflection types and static prop...
CVE-2024-54795MEDIUM5.4SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the works...
CVE-2024-54794CRITICAL9.1The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
CVE-2024-54792MEDIUM6.1A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An ...
CVE-2024-45687LOW2.4Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in Payara Pl...
CVE-2024-57036HIGH8.1TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main f...
CVE-2024-56990MEDIUM4.5PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /view-medhistory.php and /admin...
CVE-2024-56998MEDIUM4.2PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /edit-profile.php via the param...
CVE-2024-56997MEDIUM4.2PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /doctor/index.php via the 'Emai...
CVE-2024-53829HIGH8.2CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ...
CVE-2024-56277MEDIUM5.3Improper Encoding or Escaping of Output vulnerability in Ays Pro Poll Maker poll-maker.This issue affects Poll Maker: fr...
CVE-2024-51919CRITICAL9Unrestricted Upload of File with Dangerous Type vulnerability in radykal Fancy Product Designer fancy-product-designer.T...
CVE-2024-51888CRITICAL9.8Incorrect Privilege Assignment vulnerability in favethemes Homey Login Register homey-login-register allows Privilege Es...
CVE-2024-51818CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in radykal Fancy Prod...
CVE-2024-49700HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reputeinfosystems ...
CVE-2024-49699HIGH8.8Deserialization of Untrusted Data vulnerability in reputeinfosystems ARPrice arprice allows Object Injection.This issue ...
CVE-2024-49688CRITICAL9.8Deserialization of Untrusted Data vulnerability in reputeinfosystems ARPrice arprice allows Object Injection.This issue ...
CVE-2024-49666HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems ...
CVE-2024-49655CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reputeinfosystems ...
CVE-2024-49333HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Hero Mega...
CVE-2024-49303HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NotFound Hero Mega...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now