2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25211 | CRITICAL | 9.8 | 0.8% | Feb 14, 2024 | Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpo... |
| CVE-2024-25210 | CRITICAL | 9.8 | 0.8% | Feb 14, 2024 | Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoi... |
| CVE-2024-25209 | CRITICAL | 9.8 | 0.8% | Feb 14, 2024 | Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident param... |
| CVE-2024-23786 | CRITICAL | 9.3 | 0.8% | Feb 14, 2024 | Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and... |
| CVE-2024-24691 | CRITICAL | 9.8 | 1.7% | Feb 14, 2024 | Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Wind... |
| CVE-2024-1485 | CRITICAL | 9.3 | 0.9% | Feb 14, 2024 | A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated re... |
| CVE-2024-24142 | CRITICAL | 9.8 | 1.1% | Feb 13, 2024 | Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter. |
| CVE-2024-1378 | CRITICAL | 9.1 | 2.3% | Feb 13, 2024 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol... |
| CVE-2024-1374 | CRITICAL | 9.1 | 2.6% | Feb 13, 2024 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol... |
| CVE-2024-1372 | CRITICAL | 9.1 | 2.3% | Feb 13, 2024 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol... |
| CVE-2024-1369 | CRITICAL | 9.1 | 2.3% | Feb 13, 2024 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol... |
| CVE-2024-1359 | CRITICAL | 9.1 | 2.3% | Feb 13, 2024 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol... |
| CVE-2024-1355 | CRITICAL | 9.1 | 2.4% | Feb 13, 2024 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol... |
| CVE-2024-21413 | CRITICAL | 9.8 | 94.7% | Feb 13, 2024 | Microsoft Outlook Remote Code Execution Vulnerability |
| CVE-2024-21410 | CRITICAL | 9.8 | 12.7% | Feb 13, 2024 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2024-21403 | CRITICAL | 9 | 1.3% | Feb 13, 2024 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability |
| CVE-2024-21401 | CRITICAL | 9.8 | 1.5% | Feb 13, 2024 | Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability |
| CVE-2024-21376 | CRITICAL | 9 | 1.2% | Feb 13, 2024 | Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability |
| CVE-2024-21364 | CRITICAL | 9.3 | 0.6% | Feb 13, 2024 | Microsoft Azure Site Recovery Elevation of Privilege Vulnerability |
| CVE-2024-22923 | CRITICAL | 9.8 | 0.7% | Feb 13, 2024 | SQL injection vulnerability in adv radius v.2.2.5 allows a local attacker to execute arbitrary code via a crafted script... |
| CVE-2024-23816 | CRITICAL | 9.8 | 0.7% | Feb 13, 2024 | A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3),... |
| CVE-2024-23813 | CRITICAL | 9.8 | 0.6% | Feb 13, 2024 | A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The REST API endpoints of doorsconnector o... |
| CVE-2024-23810 | CRITICAL | 9.8 | 0.7% | Feb 13, 2024 | A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP1). The affected application is vulnerable to SQ... |
| CVE-2024-23763 | CRITICAL | 9.8 | 0.6% | Feb 12, 2024 | SQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET req... |
| CVE-2024-23761 | CRITICAL | 9.8 | 0.7% | Feb 12, 2024 | Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email templat... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now