2024 CVE Vulnerabilities
39,221 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-57035 | CRITICAL | 9.8 | 0.5% | Jan 17, 2025 | WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php. |
| CVE-2024-57033 | MEDIUM | 6.1 | 0.3% | Jan 17, 2025 | WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php. |
| CVE-2024-57372 | MEDIUM | 6.1 | 0.4% | Jan 17, 2025 | Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive inform... |
| CVE-2024-57370 | MEDIUM | 6.1 | 0.4% | Jan 17, 2025 | Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain se... |
| CVE-2024-57369 | MEDIUM | 6.4 | 0.3% | Jan 17, 2025 | Clickjacking vulnerability in typecho v1.2.1. |
| CVE-2024-57034 | CRITICAL | 9.8 | 0.6% | Jan 17, 2025 | WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter. |
| CVE-2024-57032 | CRITICAL | 9.8 | 0.6% | Jan 17, 2025 | WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the v... |
| CVE-2024-57031 | CRITICAL | 9.8 | 0.6% | Jan 17, 2025 | WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter. |
| CVE-2024-57030 | HIGH | 8.1 | 0.6% | Jan 17, 2025 | Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter. |
| CVE-2024-52870 | HIGH | 7.1 | 0.2% | Jan 17, 2025 | Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unin... |
| CVE-2024-13026 | MEDIUM | 6.1 | 0.1% | Jan 17, 2025 | A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The ... |
| CVE-2024-12757 | HIGH | 8.8 | 0.5% | Jan 17, 2025 | Nedap Librix Ecoreader is missing authentication for critical functions that could allow an unauthenticated attacker ... |
| CVE-2024-54681 | LOW | 3.5 | 0.3% | Jan 17, 2025 | Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an att... |
| CVE-2024-53683 | MEDIUM | 5.6 | 0.2% | Jan 17, 2025 | A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An... |
| CVE-2024-45832 | MEDIUM | 4.3 | 0.3% | Jan 17, 2025 | Hard-coded credentials were included as part of the application binary. These credentials served as part of the applica... |
| CVE-2024-26157 | MEDIUM | 6.1 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting... |
| CVE-2024-26156 | MEDIUM | 6.1 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting... |
| CVE-2024-26155 | HIGH | 8.6 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 expose clear text credentials in the web portal.... |
| CVE-2024-26154 | MEDIUM | 6.1 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting... |
| CVE-2024-26153 | HIGH | 7.4 | 0.2% | Jan 17, 2025 | All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (C... |
| CVE-2024-50967 | MEDIUM | 6.5 | 1.6% | Jan 17, 2025 | The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability.... |
| CVE-2024-13503 | CRITICAL | 9.5 | 0.5% | Jan 17, 2025 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Newtec NTC2218, NTC2250, NTC2299... |
| CVE-2024-13502 | CRITICAL | 9.3 | 0.6% | Jan 17, 2025 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Newtec/iDire... |
| CVE-2024-12703 | HIGH | 8.5 | 0.3% | Jan 17, 2025 | CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity an... |
| CVE-2024-12142 | HIGH | 8.8 | 0.3% | Jan 17, 2025 | CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information di... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now