2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-57035CRITICAL9.8WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.
CVE-2024-57033MEDIUM6.1WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php.
CVE-2024-57372MEDIUM6.1Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive inform...
CVE-2024-57370MEDIUM6.1Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain se...
CVE-2024-57369MEDIUM6.4Clickjacking vulnerability in typecho v1.2.1.
CVE-2024-57034CRITICAL9.8WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.
CVE-2024-57032CRITICAL9.8WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the v...
CVE-2024-57031CRITICAL9.8WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.
CVE-2024-57030HIGH8.1Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.
CVE-2024-52870HIGH7.1Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unin...
CVE-2024-13026MEDIUM6.1A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The ...
CVE-2024-12757HIGH8.8Nedap Librix Ecoreader is missing authentication for critical functions that could allow an unauthenticated attacker ...
CVE-2024-54681LOW3.5Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an att...
CVE-2024-53683MEDIUM5.6A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An...
CVE-2024-45832MEDIUM4.3Hard-coded credentials were included as part of the application binary. These credentials served as part of the applica...
CVE-2024-26157MEDIUM6.1All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting...
CVE-2024-26156MEDIUM6.1All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting...
CVE-2024-26155HIGH8.6All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 expose clear text credentials in the web portal....
CVE-2024-26154MEDIUM6.1All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting...
CVE-2024-26153HIGH7.4All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (C...
CVE-2024-50967MEDIUM6.5The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability....
CVE-2024-13503CRITICAL9.5Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Newtec NTC2218, NTC2250, NTC2299...
CVE-2024-13502CRITICAL9.3Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Newtec/iDire...
CVE-2024-12703HIGH8.5CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity an...
CVE-2024-12142HIGH8.8CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information di...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now