2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23674 | CRITICAL | 9.6 | 0.7% | Feb 15, 2024 | The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication byp... |
| CVE-2024-23479 | CRITICAL | 9.6 | 5.8% | Feb 15, 2024 | SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulner... |
| CVE-2024-23477 | CRITICAL | 9.6 | 7.8% | Feb 15, 2024 | The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vu... |
| CVE-2024-23476 | CRITICAL | 9.6 | 7.1% | Feb 15, 2024 | The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vu... |
| CVE-2024-25502 | CRITICAL | 9.8 | 1.4% | Feb 15, 2024 | Directory Traversal vulnerability in flusity CMS v.2.4 allows a remote attacker to execute arbitrary code and obtain sen... |
| CVE-2024-23113 | CRITICAL | 9.8 | 61.7% | Feb 15, 2024 | A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.... |
| CVE-2024-20720 | CRITICAL | 9.1 | 3.7% | Feb 15, 2024 | Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special E... |
| CVE-2024-20719 | CRITICAL | 9.1 | 1.3% | Feb 15, 2024 | Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vul... |
| CVE-2024-20738 | CRITICAL | 9.8 | 1.1% | Feb 15, 2024 | Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability ... |
| CVE-2024-0390 | CRITICAL | 9.8 | 0.4% | Feb 15, 2024 | INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by ... |
| CVE-2024-26264 | CRITICAL | 9.8 | 0.8% | Feb 15, 2024 | EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page... |
| CVE-2024-26261 | CRITICAL | 9.8 | 0.7% | Feb 15, 2024 | The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulner... |
| CVE-2024-26260 | CRITICAL | 9.8 | 1.6% | Feb 15, 2024 | The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, all... |
| CVE-2024-24300 | CRITICAL | 9.8 | 0.8% | Feb 14, 2024 | 4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardle... |
| CVE-2024-25223 | CRITICAL | 9.8 | 0.6% | Feb 14, 2024 | Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminV... |
| CVE-2024-25222 | CRITICAL | 9.8 | 0.7% | Feb 14, 2024 | Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManage... |
| CVE-2024-25220 | CRITICAL | 9.8 | 0.7% | Feb 14, 2024 | Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/E... |
| CVE-2024-25217 | CRITICAL | 9.8 | 0.7% | Feb 14, 2024 | Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /om... |
| CVE-2024-25216 | CRITICAL | 9.8 | 0.7% | Feb 14, 2024 | Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /apro... |
| CVE-2024-25215 | CRITICAL | 9.8 | 0.7% | Feb 14, 2024 | Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aproces... |
| CVE-2024-25214 | CRITICAL | 9.8 | 1.0% | Feb 14, 2024 | An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload int... |
| CVE-2024-25211 | CRITICAL | 9.8 | 0.8% | Feb 14, 2024 | Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpo... |
| CVE-2024-25210 | CRITICAL | 9.8 | 0.8% | Feb 14, 2024 | Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoi... |
| CVE-2024-25209 | CRITICAL | 9.8 | 0.8% | Feb 14, 2024 | Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident param... |
| CVE-2024-23786 | CRITICAL | 9.3 | 0.8% | Feb 14, 2024 | Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now