2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2024-25100CRITICAL9.8Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program allows Object Injection.This issue ...
CVE-2024-25722CRITICAL9.8qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection.
CVE-2024-25718CRITICAL9.8In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which int...
CVE-2024-25714CRITICAL9.8In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attack...
CVE-2024-23724CRITICAL9Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any acco...
CVE-2024-25316CRITICAL9.8Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?...
CVE-2024-25315CRITICAL9.8Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2...
CVE-2024-25314CRITICAL9.8Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2.
CVE-2024-25307CRITICAL9.8Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/boo...
CVE-2024-25302CRITICAL9.8Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.
CVE-2024-25678CRITICAL9.8In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
CVE-2024-25675CRITICAL9.8An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process...
CVE-2024-25674CRITICAL9.8An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the...
CVE-2024-21762CRITICAL9.8A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0...
CVE-2024-24308CRITICAL9.8SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows re...
CVE-2024-1353CRITICAL9.8A vulnerability, which was classified as critical, has been found in PHPEMS up to 1.0. Affected by this issue is the fun...
CVE-2024-24393CRITICAL9.8File Upload vulnerability index.php in Pichome v.1.1.01 allows a remote attacker to execute arbitrary code via crafted P...
CVE-2024-24496CRITICAL9.8An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php,...
CVE-2024-24495CRITICAL9.8SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbit...
CVE-2024-22836CRITICAL9.8An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company loc...
CVE-2024-0242CRITICAL9.8Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access ...
CVE-2024-24321CRITICAL9.8An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 pa...
CVE-2024-24213CRITICAL9.8Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/que...
CVE-2024-25191CRITICAL9.8php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authent...
CVE-2024-25190CRITICAL9.8l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authent...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now