2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-30616HIGH8.8Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sens...
CVE-2024-51329HIGH8.8A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user in...
CVE-2024-51326HIGH7.5SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrar...
CVE-2024-51127HIGH7.1An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensit...
CVE-2024-48336HIGH8.4The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app b...
CVE-2024-48809HIGH7.5An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a ...
CVE-2024-51626HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chenyenming Woocom...
CVE-2024-45893HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...
CVE-2024-45891HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...
CVE-2024-45890HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when ...
CVE-2024-45889HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...
CVE-2024-45888HIGH8DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parame...
CVE-2024-45887HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...
CVE-2024-45885HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...
CVE-2024-45884HIGH8DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when...
CVE-2024-45882HIGH8DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parame...
CVE-2024-51672HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper Better...
CVE-2024-51582HIGH8.8Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion...
CVE-2024-51253HIGH8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51251HIGH8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51249HIGH8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-51246HIGH8In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman...
CVE-2024-50530HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Stars SMTP Mailer stars-smtp-mailer al...
CVE-2024-50529HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in rudrainn Training – Courses training allows Upload a We...
CVE-2024-50528HIGH7.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Bui...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now